Repository navigation
Fix sync failing on private workspace packages without a version - #68
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Important
Two errors in dependency resolution need correction before merge: valid local packages can fail sync, and versionless workspace packages can take a different package's version.
Reviewed changes This review covers the JavaScript manifest reader, its add and sync callers, the regression tests, and the patch changeset.
- Optional installed version: Installed manifests can omit
versionwithout a schema error. - Local specifiers: Dependencies with
link:,file:, orportal:skip installed manifest lookup when no locked version exists. - Tests and release note: New tests cover a versionless workspace symlink and malformed local manifests; a changeset records the patch.
Validation: pnpm run test passed with 297 tests passed and 2 skipped. pnpm run check passed. Separate checks without network access confirmed both findings below.
gpt-6.1-sol | 𝕏
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes This review covers 639a28d, the changes since the previous Pullfrog review at ec92d38.
- Stopped ancestor lookup: Selected the nearest installed manifest before checking its version, so a missing or invalid version cannot use a different package's version from a parent directory.
- Restored local version lookup: Kept valid installed versions for
link:,file:, andportal:dependencies when no package-manager lockfile supplies a version. - Strengthened regression tests: Checked a versionless workspace symlink with a versioned package of the same name at the workspace root, and checked the exact installed version of a
file:dependency. - Updated the release note: Described the nearest-installed-package behavior instead of the removed local-specifier skip.
Validation: pnpm run test passed with 295 tests passed and 2 skipped. pnpm run check and pnpm exec tsc --noEmit -p tsconfig.json passed.
gpt-6.1-sol | 𝕏

In a monorepo,
packref syncfailed with "Failed to read or parse package manifest" fornode_modules/@tooling/linting/package.json, although the file was valid JSON. The package was a private workspace package (workspace:*) with noversionfield. Packref could not get a version from the lockfile, so it read the package'snode_modulesmanifest. A missingversionfailed schema decoding, and that failure stopped the whole sync.Now a missing
versiongives no exact version, and sync continues. Thenode_moduleslookup also stops at the nearest installed package, as in Node resolution. A versionless workspace package therefore cannot take the version of a different package with the same name in a parentnode_modules.New tests cover a symlinked versionless workspace package with a versioned package of the same name at the workspace root, and a
file:dependency that keeps its installed version. Both tests fail on the previous head of this branch.Changes made by Claude Opus 5.5 (1M context) in Claude Code (T3 Code).
🤖 Generated with Claude Code