fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(server): pnpm-global provider updates no longer leave a broken CLI - #8363

Open
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build
Open

fix(server): pnpm-global provider updates no longer leave a broken CLI#8363
angelovdev wants to merge 3 commits into
pingdotgg:mainfrom
angelovdev:fix/pnpm-global-provider-update-allow-build

Conversation

@angelovdev

@angelovdevangelovdev commented Aug 27, 2026

Copy link
Copy Markdown

Problem

pnpm 10 and later block install scripts by default. The one-click provider update runs pnpm add -g <package>@latest, so for any provider whose postinstall is what finishes the install (fetching or unpacking a platform-native binary over a stub), pnpm skips that step and still exits 0. The user gets a "successful" update and a global CLI that no longer runs.

This is the pnpm counterpart of the npm path fixed in #5646, which noted the pnpm and bun paths carried the same class of exposure and deliberately left them alone.

Fix

makePnpmGlobalProviderMaintenanceCapabilities now passes --allow-build=<packageName>, scoped to exactly the package being updated. Two existing test expectations pick up the flag. No other update path changes.

Compatibility

Worth a reviewer's attention, because pnpm differs from npm here: pnpm rejects unknown options outright rather than warning and continuing. I confirmed on 11.10.0 that pnpm add -g --totally-bogus-flag-xyz cowsay exits with [ERROR] Unknown option, while --allow-build=<pkg> is accepted.

--allow-build landed in pnpm 10.4 (February 2025). On 10.3 and older, this turns a silent partial install into a hard failure on the update. I think a loud failure is the better outcome, and it is still recoverable by hand, but it is a real behavior change that the npm fix did not carry. Happy to version-gate instead if you would rather not raise the floor.

Not covered

bun i -g gates lifecycle scripts behind a trusted-dependencies allowlist and has the same exposure. Left out to keep this to one concern.

Verification

apps/server/src/provider/providerMaintenance.test.ts passes, 18/18. Lint and format clean on both touched files.


Note

Medium Risk
Changes the shell command executed for in-app provider updates on pnpm installs; older pnpm versions without --allow-build will fail the update instead of silently skipping scripts.

Overview
Fixes one-click pnpm global provider updates so they no longer report success while leaving a broken CLI when the package needs a postinstall/build step (pnpm 10+ blocks those by default).

makePnpmGlobalProviderMaintenanceCapabilities now adds a package-scoped --allow-build=<npmPackageName> to the generated pnpm add -g …@latest command and args, mirroring the existing npm --allow-scripts behavior. Two provider maintenance tests were updated to expect the new flag.

Reviewed by Cursor Bugbot for commit 71d8048. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add --allow-build=<package> flag to pnpm-global provider update commands

Updates makePnpmGlobalProviderMaintenanceCapabilities in providerMaintenance.ts to insert the package-scoped --allow-build=<npmPackageName> flag into updateArgs, placed between -g and <pkg>@latest. This prevents pnpm global updates from leaving a broken CLI after updating packages that require a build step. Test assertions in providerMaintenance.test.ts are updated to expect the new flag and args.

Macroscope summarized 71d8048.

pnpm blocks install scripts by default, so a one-click provider update
through pnpm can replace a working global CLI with a broken one and still
report success. Scope an --allow-build allowlist to the package being
updated, matching the npm-global fix in pingdotgg#5646.
@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f23da5da-f1cb-4c61-bac1-8ea1c5b195d6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
macroscopeapp[bot]
macroscopeappBot previously approved these changes Aug 27, 2026
@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at f56c567

Macroscope's review found this PR approvable — This is a narrowly scoped two-file fix that updates only pnpm-global provider commands to allow build steps for the exact package being updated, with matching tests and no changes to other update paths. Older pnpm versions may fail explicitly on the new option, but the impact is bounded and avoids silently leaving updated CLIs unusable.

You can add or adjust custom eligibility rules. Learn more.

@macroscopeapp
macroscopeappBot dismissed their stale reviewAugust 27, 2026 07:36

Dismissing prior approval to re-evaluate f56c567

@github-actionsgithub-actionsBot added size:XS 0-9 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS0-9 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@angelovdev