
pnpm-upgrade
β Officialβ 3,334by openai Β· part of openai/openai-agents-js
Keep pnpm current: run pnpm self-update/corepack prepare, align packageManager in package.json, and bump pnpm/action-setup + pinned pnpm versions in .github/workflows to the latest release. Use this when refreshing the pnpm toolchain manually or in automation.
This is the playbook your agent receives when the skill activates β you don't need to read it to use the skill, but it's here to audit before installing.
pnpm Upgrade
Use these steps to update pnpm and CI pins without blunt search/replace.
Steps (run from repo root)
-
Resolve the target pnpm release
- Query the npm registry before changing the local toolchain:
PNPM_VERSION=$(curl -fsSL https://registry.npmjs.org/pnpm/latest | jq -r .version). - Abort if the version is missing.
- Resolve the exact package integrity:
curl -fsSL "https://registry.npmjs.org/pnpm/${PNPM_VERSION}" | jq -r .dist.integrity. - Store the result as
PNPM_INTEGRITY. - Abort if the integrity is missing or does not start with
sha512-. - Convert the base64 digest after
sha512-to lowercase hex, for example:printf '%s' "${PNPM_INTEGRITY#sha512-}" | base64 -d | xxd -p -c 256 - Store the result as
PNPM_SHA512_HEX.
- Query the npm registry before changing the local toolchain:
-
Find the target pnpm/action-setup release
- Query GitHub API:
curl -fsSL https://api.github.com/repos/pnpm/action-setup/releases/latest | jq -r .tag_name. - Use
GITHUB_TOKEN/GH_TOKENif available for higher rate limits. - Store as
ACTION_TAG(e.g.,v4.2.0). Abort if missing.
- Query GitHub API:
-
Resolve the action tag to an immutable commit SHA
- Run
git ls-remote https://github.com/pnpm/action-setup "refs/tags/${ACTION_TAG}^{}"and capture the SHA asACTION_SHA. - If the dereferenced tag is missing, fall back to
git ls-remote https://github.com/pnpm/action-setup "refs/tags/${ACTION_TAG}". - Abort if
ACTION_SHAis empty.
- Run
-
Preflight the release and CI installation path
- Run
node .agents/skills/pnpm-upgrade/scripts/preflight.mjs --version "${PNPM_VERSION}" --action-ref "${ACTION_SHA}". - The script first rejects published pnpm manifests with non-empty
dependenciesordevDependencies. pnpm bundles its runtime dependencies, so these fields indicate a broken publication such aspnpm@11.12.0. - It then reproduces both
pnpm/action-setupinstallation paths in separate temporary directories: install the regularpnpmbootstrap frompnpm-lock.jsonand the standalone@pnpm/exebootstrap fromexe-lock.json, set isolatedPNPM_HOMEdirectories, and self-update each bootstrap toPNPM_VERSION. - Abort the upgrade on any failure. Do not bypass this check with a direct local install; the preflight exists to exercise the CI-only bootstrap path.
- Run
-
Update pnpm locally
- Run
pnpm self-update "${PNPM_VERSION}". - If pnpm is missing or self-update fails only because the current installation cannot update itself, run
corepack prepare "pnpm@${PNPM_VERSION}" --activate. Do not use this fallback to bypass a failed preflight. - Confirm
pnpm -vexactly matchesPNPM_VERSION.
- Run
-
Align package.json
- Open
package.jsonand setpackageManagertopnpm@${PNPM_VERSION}+sha512.${PNPM_SHA512_HEX}(preserve trailing newline and formatting).
- Open
-
Update workflows carefully (no broad regex)
- Files: everything under
.github/workflows/that usespnpm/action-setup. - For each file, edit by hand:
- Set
uses: pnpm/action-setup@${ACTION_SHA}. - If a
with: version:field exists, set it to${PNPM_VERSION}(keep quoting style/indent).
- Set
- Do not touch unrelated steps. Avoid multiline sed/perl one-liners.
- Files: everything under
-
Verify
- Run
pnpm -vand confirm it matches the version portion ofpackageManager. - Confirm
packageManagerkeeps the exact+sha512.${PNPM_SHA512_HEX}suffix. git diffto ensure only intended workflow/package.json changes.
- Run
-
Follow-up
- If runtime code/build/test config was changed (not typical here), run
$code-change-verification; otherwise, a light check is enough. - Commit with
chore: upgrade pnpm toolchainand open a PR (automation may do this).
- If runtime code/build/test config was changed (not typical here), run
Notes
- Tools needed:
curl,jq,base64,xxd,node,npm, andpnpm/corepack. Install if missing. - Keep edits minimal and readableβprefer explicit file edits over global replacements.
- GitHub Actions must stay pinned to commit SHAs, not tags. Use the latest release tag only to discover the commit SHA to pin.
- If GitHub API is rate-limited, retry with a token or bail out rather than guessing the tag.
npx skills add openai/openai-agents-js --skill "pnpm-upgrade" --full-depthRun this in your project β your agent picks the skill up automatically.
No common issues documented yet. If you hit a problem, the repository's GitHub Issues page is the best place to look.
Licensed under MITβ you can use, modify, and redistribute it under that license's terms.
View the full license file on GitHub β