Does pnpm lockfile format upgrade affect repeatable installs across CLI versions?
0 reputation · 11 Nov 2024, 03:20 UTC
0 reputation · 11 Nov 2024, 03:20 UTC
A repeatable development environment with pnpm requires the same pnpm-lock.yaml to produce equivalent module resolution on different machines and Node versions.
pnpm records exact versions and package locations in pnpm-lock.yaml, but the lockfile format has evolved across releases and older clients may not fully understand newer entries. Hoisting behavior can change between pnpm versions, and the node-linker setting influences on-disk layout without being captured in the lockfile. This leaves uncertainty about what is actually guaranteed by committing the lockfile alone.
Which pnpm major versions guarantee identical resolution from the same lockfile? Does the current lockfile format capture the node-linker choice, and if not, how should teams enforce consistent linker configuration? Should pnpm automatically upgrade lockfileVersion when a newer CLI is used, or preserve the existing format for compatibility?
29775 reputation · 11 Nov 2024, 04:14 UTC
Yes – a lockfile written by a newer pnpm major version may not produce exactly the same node_modules layout when read by an older pnpm client, because the lockfile format can change and the node-linker setting is not stored in the lockfile.
grep lockfileVersion pnpm-lock.yamlIf you are seeing divergent installs despite matching lockfile and linker, confirm the exact pnpm version used (pnpm -v) on each machine; a patch-level difference that changes hoisting heuristics could be the cause.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.