Skip to content

chore: move to pnpm and Node 24, update toolchain, drop unused deps - #531

Merged
christianmat merged 2 commits into
mainfrom
chore/pnpm-node24-modernize
Oct 8, 2026
Merged

christianmat merged 2 commits into
mainfrom
chore/pnpm-node24-modernize

Conversation

@christianmat

Copy link
Copy Markdown
Contributor

Moves the monorepo from yarn 4 to pnpm and from Node 22 to Node 24 for development and CI. The published packages are unchanged for consumers: same entry points, same dependencies and ranges, same runtime output, and type declarations that only differ cosmetically.

What changed

Package manager

  • yarn 4.1.1 → pnpm 10.34.6 (packageManager, pnpm-workspace.yaml, pnpm-lock.yaml)
  • root resolutions → pnpm.overrides (security pins kept; brace-expansion pins moved to patched versions)
  • linkWorkspacePackages: true so @frigade/react builds and tests against the local @frigade/js, as yarn did. Published manifests still carry the plain ^0.9.12 range (checked with pnpm pack).
  • removed .yarn/, .yarnrc.yml, yarn.lock, .gitattributes (yarn-only) and the stale packages/react/release-local.sh

CI and release

  • all four workflows use pnpm/action-setup + setup-node with .nvmrc (Node 24) and the pnpm cache
  • release workflows run pnpm version-packages, which is now changeset version && pnpm install --lockfile-only. Without that, a Version Packages PR would leave the lockfile stale and break --frozen-lockfile.
  • pnpm release publishes through pnpm publish (changesets adds --no-git-checks). NPM_CONFIG_PROVENANCE=true on the main release keeps the signed provenance the npm CLI was adding. Canary has no id-token permission, so it stays without provenance as before.

Toolchain

  • TypeScript 4.9 → 5.9, Jest 29 → 30, ts-jest 29.4, @types/jest 30, @types/node 24
  • tsup stays on 6. tsup 8 changed the runtime behavior of the @frigade/js bundle enough to break Storybook interaction tests, so it is out of scope here.

Cleanup

  • removed husky (root .husky, prepare script) and unused devDependencies: lint-staged, typedoc + typedoc-plugin-markdown, jest-config, prop-types, cross-fetch, copyfiles, react-test-renderer, @storybook/testing-library, @storybook/cli, @types/dompurify (dompurify ships types), plus the unused babel setup in js-api
  • declared dependencies that were only reachable through hoisting: embla-carousel (type import), eslint-plugin-react-hooks (used by the react eslint config)
  • Card now types its forwardRef generics explicitly, which TS 5.9 needs. The exported CardComponent type is unchanged.

Verification

  • pnpm install --frozen-lockfile, pnpm build, pnpm turbo test: pass (js 28 passed / 12 skipped, react 17 passed)
  • Storybook build + test-storybook: 65 passed / 2 skipped, matching main
  • Compared against a yarn build of main:
    • ESM/CJS bundles import the same external modules
    • .d.ts output is equivalent: export { type X } modifiers (needs TS 4.5+ in consumers), and BoxProps printed without its default generic argument
  • pnpm audit: 14 → 10. All remaining advisories are dev-only: the private legacy reactv1 Storybook 7 toolchain, transitive deps of @changesets/cli with no fixed release, and tsup/esbuild.

- yarn 4 -> pnpm 10 workspace; resolutions -> pnpm.overrides
- link @frigade/js from the workspace like yarn did (linkWorkspacePackages)
- CI and release workflows on pnpm and Node 24 (.nvmrc)
- version-packages also refreshes pnpm-lock.yaml so frozen installs keep passing
- keep npm provenance on release (NPM_CONFIG_PROVENANCE)
- TypeScript 5.9, Jest 30, ts-jest 29.4; tsup stays on 6 (8 changed runtime behavior)
- remove husky, lint-staged, typedoc, babel (js-api), and other unused devDependencies
- declare embla-carousel and eslint-plugin-react-hooks where they are imported
- type Card's forwardRef explicitly for TS 5.9
npx doesn't fetch wait-on under pnpm's layout and fails with 'not found'.
@christianmat
christianmat merged commit 8f86aeb into main Oct 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants