pnpm-workspace.yaml 1.3 KB

123456789101112131415161718192021222324252627282930313233
  1. packages:
  2. - vendor/*
  3. - packages/*/*
  4. # Deploy root of the single-exe build: a pure dependency manifest whose
  5. # closure is what the exe bundles and what the Python runtime distributes.
  6. - python/sdk-runtime
  7. peerDependencyRules:
  8. allowedVersions:
  9. typescript: '>=5 <7'
  10. # pnpm 10+ blocks any dependency shipping an install/build script until it is
  11. # explicitly reviewed here (strictDepBuilds defaults to true: an unlisted script
  12. # is a hard install error). Every such package MUST be listed; we deny by
  13. # default and only allow scripts we need. esbuild (native binary) and lefthook
  14. # (git hooks) genuinely need theirs.
  15. allowBuilds:
  16. esbuild: true
  17. lefthook: true
  18. # Pulled in by @earendil-works/pi-ai (optional LLM API backend). pnpm lists
  19. # them only because they ship lifecycle scripts, but those are no-ops we don't
  20. # need, so we deny them — install still succeeds.
  21. '@google/genai': false
  22. protobufjs: false
  23. # The Landlock launcher family is our own sibling-repo release, consumed
  24. # fresh (hours old at each coordinated bump) — the release-age quarantine
  25. # would block every such bump, so the family is exempted BY NAME, not by
  26. # pinned version.
  27. minimumReleaseAgeExclude:
  28. - node-addon-landlock-run
  29. - node-addon-landlock-run-linux-arm64
  30. - node-addon-landlock-run-linux-x64