Skip to content

Fix sync failing on private workspace packages without a version - #68

Merged
adelrodriguez merged 2 commits into
mainfrom
t3code/fix-monorepo-dependency-inspection
Oct 2, 2026
Merged

adelrodriguez merged 2 commits into
mainfrom
t3code/fix-monorepo-dependency-inspection

Conversation

@adelrodriguez

@adelrodriguez adelrodriguez commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

In a monorepo, packref sync failed with "Failed to read or parse package manifest" for node_modules/@tooling/linting/package.json, although the file was valid JSON. The package was a private workspace package (workspace:*) with no version field. Packref could not get a version from the lockfile, so it read the package's node_modules manifest. A missing version failed schema decoding, and that failure stopped the whole sync.

Now a missing version gives no exact version, and sync continues. The node_modules lookup also stops at the nearest installed package, as in Node resolution. A versionless workspace package therefore cannot take the version of a different package with the same name in a parent node_modules.

New tests cover a symlinked versionless workspace package with a versioned package of the same name at the workspace root, and a file: dependency that keeps its installed version. Both tests fail on the previous head of this branch.


Changes made by Claude Opus 5.5 (1M context) in Claude Code (T3 Code).

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

Two errors in dependency resolution need correction before merge: valid local packages can fail sync, and versionless workspace packages can take a different package's version.

Reviewed changes This review covers the JavaScript manifest reader, its add and sync callers, the regression tests, and the patch changeset.

  • Optional installed version: Installed manifests can omit version without a schema error.
  • Local specifiers: Dependencies with link:, file:, or portal: skip installed manifest lookup when no locked version exists.
  • Tests and release note: New tests cover a versionless workspace symlink and malformed local manifests; a changeset records the patch.

Validation: pnpm run test passed with 297 tests passed and 2 skipped. pnpm run check passed. Separate checks without network access confirmed both findings below.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using gpt-6.1-sol | 𝕏

Comment thread src/lib/manifests/javascript.ts Outdated
Comment thread src/lib/manifests/javascript.ts Outdated
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes This review covers 639a28d, the changes since the previous Pullfrog review at ec92d38.

  • Stopped ancestor lookup: Selected the nearest installed manifest before checking its version, so a missing or invalid version cannot use a different package's version from a parent directory.
  • Restored local version lookup: Kept valid installed versions for link:, file:, and portal: dependencies when no package-manager lockfile supplies a version.
  • Strengthened regression tests: Checked a versionless workspace symlink with a versioned package of the same name at the workspace root, and checked the exact installed version of a file: dependency.
  • Updated the release note: Described the nearest-installed-package behavior instead of the removed local-specifier skip.

Validation: pnpm run test passed with 295 tests passed and 2 skipped. pnpm run check and pnpm exec tsc --noEmit -p tsconfig.json passed.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

@adelrodriguez
adelrodriguez merged commit 0256ae9 into main Oct 2, 2026
8 checks passed
@adelrodriguez
adelrodriguez deleted the t3code/fix-monorepo-dependency-inspection branch October 2, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant