pnpm-workspace.yaml 2.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. packages:
  2. - vendor/*
  3. - packages/*/*
  4. # The Landlock launcher is developed with its harness consumers but keeps
  5. # its native build and publication scripts under native/landlock-run.
  6. - native/landlock-run
  7. - native/landlock-run/packages/*
  8. # Product assemblies over the package tier; apps/cli owns the `dsh` bin.
  9. - apps/*
  10. - website
  11. # Deploy root of the single-exe build: a pure dependency manifest whose
  12. # closure is what the exe bundles and what the Python runtime distributes.
  13. - python/sdk-runtime
  14. # Vendored framework packages keep their upstream semver ranges, while local
  15. # builds must resolve those matching names to this workspace's pinned sources.
  16. linkWorkspacePackages: true
  17. overrides:
  18. '@deepseek-ai/cosmokit': 'link:vendor/cosmokit'
  19. '@deepseek-ai/schemastery': 'link:vendor/schemastery'
  20. peerDependencyRules:
  21. allowedVersions:
  22. typescript: '>=5 <7'
  23. # pnpm 10+ blocks any dependency shipping an install/build script until it is
  24. # explicitly reviewed here (strictDepBuilds defaults to true: an unlisted script
  25. # is a hard install error). Every such package MUST be listed; we deny by
  26. # default and only allow scripts we need. esbuild (native binary) and lefthook
  27. # (git hooks) genuinely need theirs.
  28. allowBuilds:
  29. esbuild: true
  30. lefthook: true
  31. # Cross-platform boundary for the persistent PTY backend, including ConPTY on Windows.
  32. node-pty: true
  33. # Pulled in by @earendil-works/pi-ai (optional LLM API backend). pnpm lists
  34. # them only because they ship lifecycle scripts, but those are no-ops we don't
  35. # need, so we deny them — install still succeeds.
  36. '@google/genai': false
  37. protobufjs: false
  38. node-addon-require-builtin: false
  39. # JSONL durability calls MoveFileExW with write-through publication on Windows.
  40. koffi: true
  41. # The Python runtime deploy includes the reviewed workspace postinstall that
  42. # restores the executable bit on node-pty's macOS spawn helper.
  43. '@deepseek-ai/dsh-subprocess-local@file:packages/subprocess/subprocess-local': true
  44. minimumReleaseAgeExclude:
  45. # Fresh pi-ai releases carry the model catalog updates that are the whole
  46. # point of bumping it; waiting out the release age would defeat that.
  47. - '@earendil-works/pi-ai@0.84.2'
  48. - node-addon-native-custom-loader@0.1.4
  49. - node-addon-require-builtin-darwin-arm64@0.1.4
  50. - node-addon-require-builtin-darwin-x64@0.1.4
  51. - node-addon-require-builtin-linux-arm64-gnu@0.1.4
  52. - node-addon-require-builtin-linux-x64-gnu@0.1.4
  53. - node-addon-require-builtin-win32-arm64-msvc@0.1.4
  54. - node-addon-require-builtin-win32-ia32-msvc@0.1.4
  55. - node-addon-require-builtin-win32-x64-msvc@0.1.4
  56. - node-addon-require-builtin@0.1.4
  57. patchedDependencies:
  58. node-pty@1.2.0-beta.15: patches/node-pty@1.2.0-beta.15.patch