workspace: protocol vs. version range for managing internal dependency patches
When maintaining a pnpm workspace that contains an internal package consumed by other workspace projects, teams must decide whether to reference that internal package via the workspace: protocol (e.g., "workspace:^1.0.0") or via a semantic version range (e.g., "^1.0.0") in the dependent manifests. The goal is to receive security and bug fixes published to th