Bumps pnpm 9.15.5 → 10.34.5 in all three places it is pinned
(`.tool-versions`, the root `packageManager` field, and
`codegen.Dockerfile` — pnpm 10 self-manages from `packageManager`, so a
mismatched Docker pin would make it re-download itself on every `make
generate`) and sets `minimumReleaseAge: 4320` in `pnpm-workspace.yaml`,
so a freshly published version is not resolved until it is 3 days old;
CI is unaffected because every workflow installs with
`--frozen-lockfile` and nothing installs a just-published package.
Two pnpm 10 breaking changes needed handling: dependency lifecycle
scripts no longer run by default, so `esbuild` and `workerd` are
allowlisted via `pnpm.onlyBuiltDependencies` for binary resolution while
`bufferutil`, `msw`, and `utf-8-validate` are explicitly declined via
`pnpm.ignoredBuiltDependencies` (which also keeps the "Ignored build
scripts" warning off every install); and pnpm 10 stopped public-hoisting
`*prettier*`/`*eslint*`, which broke `pnpm run format` in both JS
packages with `prettier: command not found` — prettier was never
declared anywhere and only resolved because pnpm 9 hoisted it out of
`json-schema-to-typescript`, so it is now a root devDependency alongside
`oxlint`, resolved to the 3.6.2 already in the lockfile for zero
formatting churn.
`engines.pnpm` moves to `>=10.16.0 <11` so, with `engine-strict`, pnpm 9
fails with an actionable "install the required pnpm version globally"
message instead of silently installing.
Verified with a clean `node_modules` + `--frozen-lockfile` install and
green `lint`, `typecheck`, `format`, and both JS builds, plus a
from-scratch re-resolve of the whole tree to confirm
`minimumReleaseAgeStrict` (which silently defaults to `true` once the
age is set explicitly) does not trap any current range; enforcement was
checked empirically — with the setting, `wrangler@^4` resolves to
4.118.0 (6d old) rather than 4.119.0 (1d old). The lockfile diff is
limited to the prettier entry plus pnpm 10's importer-section reordering
and new `libc:` fields, with no dependency version drift.
No changeset: nothing in a published package changed. A follow-up to
pnpm 11 is deliberately out of scope — it removes both build-script
fields in favor of `allowBuilds`, restricts `.npmrc` to auth/registry
settings, and replaces the npm-delegating `pnpm publish`, which the
release flow depends on.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
The specs in `spec/` were copied from their source repos by hand and had
drifted ~2,400 lines behind infra, so they are now imported with
Copybara (`copy.bara.sky`, run in a pinned Docker image by
`scripts/fetch-spec.sh`): `make codegen` re-fetches them at the commits
pinned in `spec/infra-ref` and `spec/belt-ref` before generating, and
the generated-files CI check fails if the tracked copies don't match the
pins. Regenerating from the current pins picks up the accumulated spec
changes in the generated JS/Python clients (renamed request schemas,
`SandboxNetworkConfig`, `SandboxIam` workload identity,
`FILE_TYPE_SYMLINK`, access-token auth deprecation, volume path-metadata
tweaks). The one handwritten SDK change follows from that: the public
`FileType` enums gain a `SYMLINK` member (JS and both Python surfaces)
so entries envd reports as symlinks show up in `files.list()` and
`getInfo()`/`get_info()` instead of being silently skipped as unknown
types. The custom `spec/remove_extra_tags.py` tag-filtering script is
replaced by Redocly CLI's `filter-in` decorator (`redocly.yaml`), which
produces identical generated JS output; a `filter-out` decorator
additionally drops any operation or component schema the upstream specs
mark `x-not-implemented: true` (currently the SOCKS5
`SandboxEgressProxyConfig`/`egressProxy` surface, which infra flagged as
spec-only); each SDK's bundle now goes to its own gitignored
`spec/openapi_generated.<api>.yml` instead of both pipelines overwriting
one shared file; Python client models now list fields in spec order
instead of alphabetical (mechanical reordering only — construct models
with keyword args). Spec fetches try whatever GitHub token is available
and fall back to the tracked copies with a warning (the public infra
specs also fetch anonymously); in CI a short-lived belt-scoped token is
minted from the org-wide Autofixer GitHub App (no new secrets), so fork
PRs simply fall back for the belt spec; the CI workflows also cache the
Copybara image alongside the codegen image, and the previously ignored
`CODEGEN_IMAGE` env is honored by the Makefile.
## Usage
```sh
# update the specs: bump a pin, then regenerate
echo <infra-commit-sha> > spec/infra-ref
make codegen
# fetch a single spec without regenerating
pnpm fetch:api-spec # spec/openapi.yml from infra
pnpm fetch:envd-spec # spec/envd/ from infra
pnpm fetch:volume-spec # spec/openapi-volumecontent.yml from belt
# try the latest spec without touching the pin
E2B_INFRA_REF=main pnpm fetch:api-spec
# change which endpoint tags an SDK exposes
$EDITOR redocly.yaml && make codegen
```
```ts
// symlinks are now visible in the filesystem API (JS; same shape in Python)
const entries = await sandbox.files.list('/home/user')
const link = entries.find((e) => e.type === FileType.SYMLINK)
console.log(link?.symlinkTarget)
```
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
## Summary
- Add `spec/` to the pnpm workspace with a `package.json` that runs
`prettier --check`/`--write` on `openapi.yml` and `envd/envd.yaml`.
- The existing Lint workflow's recursive `pnpm run lint`/`pnpm run
format` now enforces YAML formatting automatically — no workflow changes
needed.
- Reformat `spec/openapi.yml` (two `$ref` quote-style changes) so the
new check passes.
## Test plan
- [ ] CI Lint workflow passes
- [ ] `pnpm --filter @e2b/spec run lint` succeeds locally
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
<!-- CURSOR_SUMMARY -->
> [!NOTE]
> **Medium Risk**
> Medium risk because it deletes a large subtree (`apps/web`) and
removes SDK-reference generation/commit steps from the package publish
workflow, which may affect downstream docs/release expectations.
>
> **Overview**
> **Removes the docs web app and generated SDK reference content.** The
PR deletes `apps/web` configs/scripts (Next.js/MDX setup, Sentry config,
prebuild/sitemap generation) and removes the committed `sdk-reference`
MDX pages.
>
> **Simplifies repo automation and ownership.** The package publish
workflow no longer generates/clones/commits SDK reference docs,
`CODEOWNERS` drops web/docs ownership entries, and the root ESLint
config removes `@stylistic/ts` in favor of the built-in `semi` rule.
>
> <sup>Written by [Cursor
Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit
4158d777b5f3d3fa30b538e434d34ce0e697d473. This will update automatically
on new commits. Configure
[here](https://cursor.com/dashboard?tab=bugbot).</sup>
<!-- /CURSOR_SUMMARY -->