forked from Automattic/jetpack
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy path.pnpmfile.cjs
201 lines (183 loc) · 7.13 KB
/
.pnpmfile.cjs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
// Note if you change something here, you'll have to make a package.json mismatch pnpm-lock.yaml to
// get it re-run. An easy way to do that is to just edit pnpm-lock.yaml to change the version number
// of husky near the top.
/**
* Fix package dependencies.
*
* We could generally do the same with pnpm.overrides in packages.json, but this allows for comments.
*
* @param {object} pkg - Dependency package.json contents.
* @returns {object} Modified pkg.
*/
function fixDeps( pkg ) {
// Way too many dependencies, some of them vulnerable, that we don't need for the one piece of this (dist/esm/progress-bar) that we actually use.
// p1655760691502999-slack-CBG1CP4EN
if ( pkg.name === '@automattic/components' ) {
delete pkg.dependencies[ '@automattic/data-stores' ];
delete pkg.dependencies[ 'i18n-calypso' ];
delete pkg.dependencies[ 'wpcom-proxy-request' ];
}
// Depends on punycode but doesn't declare it.
// https://github.com/markdown-it/markdown-it/issues/230
if ( pkg.name === 'markdown-it' && ! pkg.dependencies.punycode ) {
pkg.dependencies.punycode = '^2.1.1';
}
// Even though Storybook works with webpack 5, they still have a bunch of deps on webpack4.
// I hear v7 is supposed to fix that <https://github.com/storybookjs/storybook/issues/18261#issuecomment-1132031458>.
if ( pkg.name.startsWith( '@storybook/' ) ) {
if ( pkg.dependencies[ '@storybook/builder-webpack4' ] ) {
pkg.dependencies[ '@storybook/builder-webpack4' ] = 'npm:@storybook/builder-webpack5@^6';
}
if ( pkg.dependencies[ '@storybook/manager-webpack4' ] ) {
pkg.dependencies[ '@storybook/manager-webpack4' ] = 'npm:@storybook/manager-webpack5@^6';
}
if ( pkg.dependencies.webpack ) {
pkg.dependencies.webpack = '^5';
}
if ( pkg.dependencies[ '@types/webpack' ] ) {
pkg.dependencies[ '@types/webpack' ] = '^5';
}
}
// Missing dep or peer dep on @wordpress/element.
// https://github.com/WordPress/gutenberg/issues/41341
// https://github.com/WordPress/gutenberg/issues/41346
if (
( pkg.name === '@wordpress/preferences' || pkg.name === '@wordpress/viewport' ) &&
! pkg.dependencies?.[ '@wordpress/element' ] &&
! pkg.peerDependencies?.[ '@wordpress/element' ]
) {
pkg.peerDependencies[ '@wordpress/element' ] = '*';
}
// Missing dep or peer dep on @babel/runtime
// https://github.com/WordPress/gutenberg/issues/41343
if (
pkg.name === '@wordpress/reusable-blocks' &&
! pkg.dependencies?.[ '@babel/runtime' ] &&
! pkg.peerDependencies?.[ '@babel/runtime' ]
) {
pkg.peerDependencies[ '@babel/runtime' ] = '^7';
}
// Turn @wordpress/eslint-plugin's eslint plugin deps into peer deps.
// https://github.com/WordPress/gutenberg/issues/39810
if ( pkg.name === '@wordpress/eslint-plugin' ) {
for ( const [ dep, ver ] of Object.entries( pkg.dependencies ) ) {
if ( dep.startsWith( 'eslint-plugin-' ) || dep.endsWith( '/eslint-plugin' ) ) {
delete pkg.dependencies[ dep ];
pkg.peerDependencies[ dep ] = ver.replace( /^\^?/, '>=' );
}
}
}
// Override @types/react* dependencies in order to use their specific versions
// @todo This is probably not safe: https://github.com/Automattic/jetpack/pull/24294#discussion_r881708463
for ( const dep of [ '@types/react', '@types/react-dom', '@types/react-test-renderer' ] ) {
if ( pkg.dependencies?.[ dep ] ) {
pkg.dependencies[ dep ] = '17.x';
}
}
// Regular expression DOS.
// Dep is via storybook, fix in v7: https://github.com/storybookjs/storybook/issues/14603#issuecomment-1105006210
if ( pkg.dependencies.trim === '0.0.1' ) {
pkg.dependencies.trim = '^0.0.3';
}
// Avoid annoying flip-flopping of sub-dep peer deps.
// https://github.com/localtunnel/localtunnel/issues/481
if ( pkg.name === 'localtunnel' ) {
for ( const [ dep, ver ] of Object.entries( pkg.dependencies ) ) {
if ( ver.match( /^\d+(\.\d+)+$/ ) ) {
pkg.dependencies[ dep ] = '^' + ver;
}
}
}
// Convert @testing-library/react's dep on @testing-library/dom to a peer.
// https://github.com/testing-library/react-testing-library/issues/906#issuecomment-1180767493
if (
( pkg.name === '@testing-library/react' || pkg.name === '@testing-library/preact' ) &&
pkg.dependencies[ '@testing-library/dom' ]
) {
pkg.peerDependencies ||= {};
pkg.peerDependencies[ '@testing-library/dom' ] = pkg.dependencies[ '@testing-library/dom' ];
delete pkg.dependencies[ '@testing-library/dom' ];
}
return pkg;
}
/**
* Fix package peer dependencies.
*
* This can't be done with pnpm.overrides.
*
* @param {object} pkg - Dependency package.json contents.
* @returns {object} Modified pkg.
*/
function fixPeerDeps( pkg ) {
// React 17 is entirely compatible with React 16, but of course abandoned packages exist...
const react16Pkgs = new Set( [
'react-dates', // @wordpress/components <https://github.com/WordPress/gutenberg/issues/21820?>
'airbnb-prop-types', // @wordpress/components → react-dates
'react-with-direction', // @wordpress/components → react-dates → react-with-styles
'react-autosize-textarea', // @wordpress/block-editor <https://github.com/WordPress/gutenberg/issues/39619>
] );
if ( react16Pkgs.has( pkg.name ) ) {
for ( const p of [ 'react', 'react-dom' ] ) {
if (
pkg.peerDependencies?.[ p ] &&
pkg.peerDependencies[ p ].match( /(?:^|\|\|\s*)(?:\^16|16\.x)/ ) &&
! pkg.peerDependencies[ p ].match( /(?:^|\|\|\s*)(?:\^17|17\.x)/ )
) {
pkg.peerDependencies[ p ] += ' || ^17';
}
}
}
// Outdated peer dependency. Major version bump was apparently the addition of TypeScript types.
// No upstream bug link yet.
if (
pkg.name === '@automattic/components' &&
pkg.peerDependencies[ '@wordpress/data' ] === '^6.1.5'
) {
pkg.peerDependencies[ '@wordpress/data' ] = '^6.1.5 || ^7.0.0';
}
return pkg;
}
/**
* Pnpm package hook.
*
* @see https://pnpm.io/pnpmfile#hooksreadpackagepkg-context-pkg--promisepkg
* @param {object} pkg - Dependency package.json contents.
* @param {object} context - Pnpm object of some sort.
* @returns {object} Modified pkg.
*/
function readPackage( pkg, context ) {
if ( pkg.name ) {
pkg = fixDeps( pkg, context );
pkg = fixPeerDeps( pkg, context );
}
return pkg;
}
/**
* Pnpm lockfile hook.
*
* @see https://pnpm.io/pnpmfile#hooksafterallresolvedlockfile-context-lockfile--promiselockfile
* @param {object} lockfile - Lockfile data.
* @returns {object} Modified lockfile.
*/
function afterAllResolved( lockfile ) {
// If there's only one "importer", it's probably pnpx rather than the monorepo. Don't interfere.
if ( Object.keys( lockfile.importers ).length === 1 ) {
return lockfile;
}
for ( const [ k, v ] of Object.entries( lockfile.packages ) ) {
// Forbid installing webpack without webpack-cli. It results in lots of spurious lockfile changes.
// https://github.com/pnpm/pnpm/issues/3935
if ( k.startsWith( '/webpack/' ) && ! v.dependencies[ 'webpack-cli' ] ) {
throw new Error(
"Something you've done is trying to add a dependency on webpack without webpack-cli.\nThis is not allowed, as it tends to result in pnpm lockfile flip-flopping.\nSee https://github.com/pnpm/pnpm/issues/3935 for the upstream bug report."
);
}
}
return lockfile;
}
module.exports = {
hooks: {
readPackage,
afterAllResolved,
},
};