From ea262e4380d879ce8869c8cc9a8602ab5c250ffd Mon Sep 17 00:00:00 2001 From: Sefa Eyeoglu Date: Sun, 24 May 2026 13:40:06 +0200 Subject: [PATCH] pnpmConfigHook: disable lockfile verification against supply-chain policies These checks are still performed in fetchPnpmDeps. These checks require access to the registries used in the lockfile, making it infeasible to run during configurePhase in a sandboxed build. Signed-off-by: Sefa Eyeoglu (cherry picked from commit 599909067c73a154d5c3a7866176d79734146555) --- pkgs/build-support/node/fetch-pnpm-deps/pnpm-config-hook.sh | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/build-support/node/fetch-pnpm-deps/pnpm-config-hook.sh b/pkgs/build-support/node/fetch-pnpm-deps/pnpm-config-hook.sh index 79c8f2d1a3a9..576954e7baf1 100644 --- a/pkgs/build-support/node/fetch-pnpm-deps/pnpm-config-hook.sh +++ b/pkgs/build-support/node/fetch-pnpm-deps/pnpm-config-hook.sh @@ -28,6 +28,11 @@ pnpmConfigHook() { if versionAtLeast "$pnpmVersion" "11"; then # pnpm 11 uses a different mechanism to manage package manager versions export pnpm_config_pm_on_fail=ignore + + # Disable lockfile verification against supply-chain policies. This is + # already done in fetchPnpmDeps, so if these checks failed there, we + # wouldn't be here in the first place + export pnpm_config_trust_lockfile=true else pnpm config set manage-package-manager-versions false fi