mirror of
https://github.com/pnpm/action-setup.git
synced 2026-08-14 05:52:09 +08:00
pnpm v11 and newer verify every lockfile entry against the configured supply-chain policies (`minimumReleaseAge`, `trustPolicy`, ...) and memoize the verdict in `<cacheDir>/lockfile-verified.jsonl`. The action cached only the store, so every job started with that verdict missing and re-checked the whole lockfile against the registry — on typescript-eslint's repository, 16.6s of a 17.6s install on Linux and 40.1s of 42.4s on Windows. The verdict depends on the lockfile content and the policies, never on the runner, so it is cached under its own key alongside the store cache and restored without prefix fallback: an entry recorded for a different lockfile could never be reused. Saving happens before `pnpm store prune`, which drops the log along with the store's other derived state. Anything that goes wrong here only costs the next job the re-verification, so failures are reported as warnings instead of failing the build. Older pnpm versions never write the log, and the post step then finds nothing to save.
46 lines
1.5 KiB
YAML
46 lines
1.5 KiB
YAML
name: Setup pnpm
|
|
description: Install pnpm package manager
|
|
branding:
|
|
icon: package
|
|
color: orange
|
|
inputs:
|
|
version:
|
|
description: Version of pnpm to install
|
|
required: false
|
|
dest:
|
|
description: Where to store pnpm files
|
|
required: false
|
|
default: ~/setup-pnpm
|
|
run_install:
|
|
description: If specified, run `pnpm install`
|
|
required: false
|
|
default: 'null'
|
|
cache:
|
|
description: |
|
|
Whether to cache the pnpm store directory and, on pnpm v11 and newer,
|
|
the results of pnpm's lockfile verification against the configured
|
|
supply-chain policies. Both are keyed on the lockfile's content hash.
|
|
required: false
|
|
default: 'false'
|
|
cache_dependency_path:
|
|
description: File path to the pnpm lockfile, whose contents hash will be used as a cache key. Accepts multiple paths delimited by newlines.
|
|
required: false
|
|
default: 'pnpm-lock.yaml'
|
|
package_json_file:
|
|
description: File path to the package.json to read "packageManager" configuration. This path must be relative to the repository root (GITHUB_WORKSPACE).
|
|
required: false
|
|
default: 'package.json'
|
|
standalone:
|
|
description: When set to true, @pnpm/exe, which is a Node.js bundled package, will be installed, enabling using pnpm without Node.js.
|
|
required: false
|
|
default: 'false'
|
|
outputs:
|
|
dest:
|
|
description: Expanded path of inputs#dest
|
|
bin_dest:
|
|
description: Location of `pnpm` and `pnpx` command
|
|
runs:
|
|
using: node24
|
|
main: dist/index.js
|
|
post: dist/index.js
|