Does pnpm lockfile format upgrade affect repeatable installs across CLI versions?
0 reputation · 11 Nov 2024, 03:20 UTC
A repeatable development environment with pnpm requires the same pnpm-lock.yaml to produce equivalent module resolution on different machines and Node versions.
pnpm records exact versions and package locations in pnpm-lock.yaml, but the lockfile format has evolved across releases and older clients may not fully understand newer entries. Hoisting behavior can change between pnpm versions, and the node-linker setting influences on-disk layout without being captured in the lockfile. This leaves uncertainty about what is actually guaranteed by committing the lockfile alone.
Which pnpm major versions guarantee identical resolution from the same lockfile? Does the current lockfile format capture the node-linker choice, and if not, how should teams enforce consistent linker configuration? Should pnpm automatically upgrade lockfileVersion when a newer CLI is used, or preserve the existing format for compatibility?