pnpmConfigHook: disable lockfile verification against supply-chain policies

These checks are still performed in fetchPnpmDeps. These checks require
access to the registries used in the lockfile, making it infeasible to
run during configurePhase in a sandboxed build.

Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
(cherry picked from commit 599909067c)
This commit is contained in:
Sefa Eyeoglu
2026-05-24 13:40:06 +02:00
committed by github-actions[bot]
parent 820ce7d303
commit ea262e4380

View File

@@ -28,6 +28,11 @@ pnpmConfigHook() {
if versionAtLeast "$pnpmVersion" "11"; then
# pnpm 11 uses a different mechanism to manage package manager versions
export pnpm_config_pm_on_fail=ignore
# Disable lockfile verification against supply-chain policies. This is
# already done in fetchPnpmDeps, so if these checks failed there, we
# wouldn't be here in the first place
export pnpm_config_trust_lockfile=true
else
pnpm config set manage-package-manager-versions false
fi