Files
e2b-dev--e2b/codegen.Dockerfile
Mish Ushakov 26ee42c10a chore: upgrade pnpm to 10.34.5 and delay fresh releases by 3 days (#1644)
Bumps pnpm 9.15.5 → 10.34.5 in all three places it is pinned
(`.tool-versions`, the root `packageManager` field, and
`codegen.Dockerfile` — pnpm 10 self-manages from `packageManager`, so a
mismatched Docker pin would make it re-download itself on every `make
generate`) and sets `minimumReleaseAge: 4320` in `pnpm-workspace.yaml`,
so a freshly published version is not resolved until it is 3 days old;
CI is unaffected because every workflow installs with
`--frozen-lockfile` and nothing installs a just-published package.

Two pnpm 10 breaking changes needed handling: dependency lifecycle
scripts no longer run by default, so `esbuild` and `workerd` are
allowlisted via `pnpm.onlyBuiltDependencies` for binary resolution while
`bufferutil`, `msw`, and `utf-8-validate` are explicitly declined via
`pnpm.ignoredBuiltDependencies` (which also keeps the "Ignored build
scripts" warning off every install); and pnpm 10 stopped public-hoisting
`*prettier*`/`*eslint*`, which broke `pnpm run format` in both JS
packages with `prettier: command not found` — prettier was never
declared anywhere and only resolved because pnpm 9 hoisted it out of
`json-schema-to-typescript`, so it is now a root devDependency alongside
`oxlint`, resolved to the 3.6.2 already in the lockfile for zero
formatting churn.

`engines.pnpm` moves to `>=10.16.0 <11` so, with `engine-strict`, pnpm 9
fails with an actionable "install the required pnpm version globally"
message instead of silently installing.

Verified with a clean `node_modules` + `--frozen-lockfile` install and
green `lint`, `typecheck`, `format`, and both JS builds, plus a
from-scratch re-resolve of the whole tree to confirm
`minimumReleaseAgeStrict` (which silently defaults to `true` once the
age is set explicitly) does not trap any current range; enforcement was
checked empirically — with the setting, `wrangler@^4` resolves to
4.118.0 (6d old) rather than 4.119.0 (1d old). The lockfile diff is
limited to the prettier entry plus pnpm 10's importer-section reordering
and new `libc:` fields, with no dependency version drift.

No changeset: nothing in a published package changed. A follow-up to
pnpm 11 is deliberately out of scope — it removes both build-script
fields in favor of `allowBuilds`, restricts `.npmrc` to auth/registry
settings, and replaces the npm-delegating `pnpm publish`, which the
release flow depends on.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 16:29:18 +02:00

48 lines
1.7 KiB
Docker

FROM golang:1.23
# Install Golang deps
RUN go install github.com/bufbuild/buf/cmd/buf@v1.50.1 && \
go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.28.1 && \
go install connectrpc.com/connect/cmd/protoc-gen-connect-go@v1.18.1
FROM python:3.10
# Set working directory
WORKDIR /workspace
# Copy installed Go deps from previous build step
COPY --from=0 /go /go
# Add Go binary to PATH
ENV PATH="/go/bin:${PATH}"
# Install Python deps (e2b-openapi-python-client is patched version to fix issue with explode)
# https://github.com/openapi-generators/openapi-python-client/pull/1296
# protoc-gen-py generates the Python envd protobuf-py messages and
# protoc-gen-connectrpc the Connect stubs.
RUN pip install black==26.3.1 e2b-openapi-python-client==0.26.2 datamodel-code-generator==0.64.0 protoc-gen-connectrpc==0.11.1 protoc-gen-py==0.1.1
# Install Node.js (pinned to match .tool-versions)
ENV NODE_VERSION=22.18.0
RUN ARCH=$(uname -m) && \
case "$ARCH" in \
x86_64) NODE_ARCH="x64" ;; \
arm64|aarch64) NODE_ARCH="arm64" ;; \
*) echo "Unsupported architecture: $ARCH" && exit 1 ;; \
esac && \
curl -fsSL https://nodejs.org/dist/v${NODE_VERSION}/node-v${NODE_VERSION}-linux-${NODE_ARCH}.tar.xz | tar -xJ -C /usr/local --strip-components=1
# Install Node.js deps
# pnpm is pinned to match .tool-versions and the root `packageManager` field —
# pnpm manages its own version from `packageManager` since v10, so a mismatch
# would make it re-download itself on every `make generate`.
ENV PNPM_VERSION=10.34.5
RUN npm install -g \
pnpm@${PNPM_VERSION} \
@connectrpc/protoc-gen-connect-es@1.6.1 \
@bufbuild/protoc-gen-es@2.6.2 \
@redocly/cli@2.39.0
CMD ["make", "generate"]