1
0
mirror of https://github.com/pnpm/action-setup.git synced 2026-08-28 21:23:45 +08:00

Compare commits

...

7 Commits

Author SHA1 Message Date
Zoltan Kochan
c0a6b0ff36 perf: cache pnpm's lockfile verification results
pnpm v11 and newer verify every lockfile entry against the configured
supply-chain policies (`minimumReleaseAge`, `trustPolicy`, ...) and memoize
the verdict in `<cacheDir>/lockfile-verified.jsonl`. The action cached only
the store, so every job started with that verdict missing and re-checked the
whole lockfile against the registry — on typescript-eslint's repository,
16.6s of a 17.6s install on Linux and 40.1s of 42.4s on Windows.

The verdict depends on the lockfile content and the policies, never on the
runner, so it is cached under its own key alongside the store cache and
restored without prefix fallback: an entry recorded for a different lockfile
could never be reused. Saving happens before `pnpm store prune`, which drops
the log along with the store's other derived state.

Anything that goes wrong here only costs the next job the re-verification, so
failures are reported as warnings instead of failing the build. Older pnpm
versions never write the log, and the post step then finds nothing to save.
2026-08-13 13:59:37 +02:00
Eric Nemchik
0977fd9972 docs: Update README to include devEngines.packageManager (#273)
Support added in #211 and #256
2026-08-03 13:44:13 +02:00
Jamie Tanna
48261aca05 fix: update pnpm to v11.19.0 (#283)
* fix: update pnpm to v11.19.0

Via `scripts/update-bootstrap.mjs 11.19.0`

Co-authored-by: Claude Sonnet 5 <jamie.tanna+claude-code@mend.io>

* fixup! fix: update pnpm to v11.19.0

As it needs to be rebuilt on Linux.

---------

Co-authored-by: Claude Sonnet 5 <jamie.tanna+claude-code@mend.io>
2026-08-03 11:54:52 +02:00
Jamie Tanna
75677f717d ci: use pnpm 11 for pr-check (#284)
Noticed while working on #283.
2026-08-03 11:02:17 +02:00
Sukka
769ae71fb3 refactor: introduce restore keys for cache (#280) 2026-08-03 10:32:23 +02:00
Kevin Cui
6fed91f804 docs(README): point users to the successor pnpm/setup action (#282)
* docs(README): point users to the successor pnpm/setup action

The pnpm setup action has moved to `pnpm/setup`, which installs
pnpm v11+ as a self-contained native executable and can install a
JavaScript runtime (Node.js, Bun, or Deno) in the same step,
replacing `actions/setup-node`.

Add a notice at the top of the README, a migration section with a
before/after workflow example and an input/output mapping table,
and mention the successor in the Notes section. The rest of the
docs stay intact since `pnpm/action-setup` remains the way to
install pnpm v10 and older.

Signed-off-by: Kevin Cui <bh@bugs.cc>

* docs(README): address review feedback on migration section

Add an explicit version: 11 to the migration example and note when the
input can be omitted, since pnpm/setup requires pnpm v11+ and a repo
migrating from version: 10 may have no packageManager field or one that
pins v10.

Move the v2 upgrade warning below the page title so the two callouts
are no longer adjacent blockquotes (markdownlint MD028), keeping the
successor notice and the legacy warning as separate blocks.

Fix the comma splice and use "set up" as the verb in the Notes
section.

Signed-off-by: Kevin Cui <bh@bugs.cc>

---------

Signed-off-by: Kevin Cui <bh@bugs.cc>
2026-08-02 22:56:56 -04:00
Zoltan Kochan
0ebf47130e fix: update pnpm to v11.7.0 (#267)
* fix: update pnpm to v11.7.0

* fix: update bundle
2026-06-15 14:04:13 +02:00
11 changed files with 435 additions and 199 deletions

View File

@@ -19,7 +19,7 @@ jobs:
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5.0.0
with:
run_install: true
version: 9
version: 11
- name: Update dist/index.js
run: pnpm run build

View File

@@ -329,3 +329,51 @@ jobs:
exit 1
fi
shell: bash
cache_lockfile_verification:
# The action caches pnpm's lockfile verification log, which lives in
# `cacheDir` — a directory pnpm resolves per platform and does not print.
# Guard the action's copy of that default against pnpm's own.
name: 'Lockfile verification cache (${{ matrix.os }})'
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Set up a project with a supply-chain policy
# A one-minute floor activates the verification without holding back
# any version the install resolves.
run: |
echo '{"dependencies":{"is-odd":"3.0.1"}}' > package.json
printf 'packages:\n - .\nminimumReleaseAge: 1\n' > pnpm-workspace.yaml
shell: bash
- uses: ./
with:
version: '12.0.0-rc.4'
cache: true
run_install: |
- args: [--no-frozen-lockfile]
- name: 'Test: pnpm wrote the verification log where the action looks for it'
run: |
set -e
case "$RUNNER_OS" in
Linux) cacheDir="${XDG_CACHE_HOME:-$HOME/.cache}/pnpm" ;;
macOS) cacheDir="$HOME/Library/Caches/pnpm" ;;
Windows) cacheDir="$(cygpath -u "$LOCALAPPDATA")/pnpm-cache" ;;
*) echo "Unexpected RUNNER_OS: $RUNNER_OS"; exit 1 ;;
esac
echo "Expecting the verification log in ${cacheDir}"
if [ ! -f "${cacheDir}/lockfile-verified.jsonl" ]; then
echo "No lockfile-verified.jsonl there; the action would cache nothing"
ls -la "${cacheDir}" || true
exit 1
fi
shell: bash

View File

@@ -1,18 +1,68 @@
> ## :warning: Upgrade from v2!
> [!IMPORTANT]
> **This action has a successor: [`pnpm/setup`](https://github.com/pnpm/setup).**
>
> The v2 version of this action [has stopped working](https://github.com/pnpm/action-setup/issues/135) with newer Node.js versions. Please, upgrade to the latest version to fix any issues.
> For pnpm v11 and newer, use [`pnpm/setup`](https://github.com/pnpm/setup) instead. It downloads pnpm's self-contained release binary (no Node.js or npm required) and can install a JavaScript runtime (Node.js, Bun, or Deno) in the same step, replacing `actions/setup-node`.
>
> `pnpm/action-setup` remains the action to use for installing pnpm v10 and older. See [Migrating to pnpm/setup](#migrating-to-pnpmsetup) below.
# Setup pnpm
Install pnpm package manager.
> ## :warning: Upgrade from v2!
>
> The v2 version of this action [has stopped working](https://github.com/pnpm/action-setup/issues/135) with newer Node.js versions. Please, upgrade to the latest version to fix any issues.
## Migrating to pnpm/setup
[`pnpm/setup`](https://github.com/pnpm/setup) installs pnpm v11+ as a native standalone executable and can install Node.js, Bun, or Deno in the same step, so a typical workflow no longer needs `actions/setup-node` or an explicit `pnpm install` step:
```yaml
steps:
- uses: actions/checkout@v6
# Before:
# - uses: pnpm/action-setup@v6
# with:
# version: 10
# cache: true
# - uses: actions/setup-node@v4
# with:
# node-version: 22
# - run: pnpm install
# After:
- uses: pnpm/setup@v1
with:
version: 11
runtime: node@22
cache: true
```
The `version` input can be omitted only when `packageManager` (or `devEngines.packageManager`) in `package.json` declares pnpm v11 or newer; otherwise keep it explicit, since `pnpm/setup` requires pnpm v11+.
Input and output changes:
| `pnpm/action-setup` | `pnpm/setup` | Notes |
| ------------------- | ------------ | ----- |
| `version` | `version` | Must resolve to pnpm v11 or newer. As before, it can be omitted when `packageManager` (or `devEngines.packageManager`) is set in `package.json`. |
| `dest` | `dest` | Unchanged. |
| `run_install` | `install` | `pnpm/setup` runs `pnpm install` automatically when a `package.json` is present (`install: true` by default); set `install: false` to skip it. The object/array form (`recursive`, `cwd`, `args`) is not supported — run those commands in separate steps. |
| `cache` | `cache` | Unchanged. |
| `cache_dependency_path` | `cache-dependency-path` | Renamed to kebab-case. |
| `package_json_file` | `package-json-file` | Renamed to kebab-case. |
| `standalone` | removed | `pnpm/setup` always installs the standalone native executable. |
| n/a | `runtime` | New: installs Node.js, Bun, or Deno (e.g. `node@22`, `bun@latest`, `deno@2`), or reads `devEngines.runtime` from `package.json`. |
| n/a | `token` | New: GitHub token for release lookup; defaults to `${{ github.token }}` and rarely needs to be set. |
| `bin_dest` (output) | `bin-dest` (output) | Renamed to kebab-case. New outputs `runtime-name` and `runtime-version` describe the installed runtime. |
## Inputs
### `version`
Version of pnpm to install.
**Optional** when there is a [`packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
**Optional** when there is a [`packageManager` or `devEngines.packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
otherwise, this field is **required** It supports npm versioning scheme, it could be an exact version (such as `10.9.8`), or a version range (such as `10`, `10.x.x`, `10.9.x`, `^10.9.8`, `*`, etc.), or `latest`.
@@ -44,7 +94,7 @@ If `run_install` is a YAML string representation of either an object or an array
### `cache`
**Optional** (_type:_ `boolean`, _default:_ `false`) Whether to cache the pnpm store directory.
**Optional** (_type:_ `boolean`, _default:_ `false`) Whether to cache the pnpm store directory and, on pnpm v11 and newer, the results of pnpm's lockfile verification against the configured supply-chain policies. Both are keyed on the lockfile's content hash.
### `cache_dependency_path`
@@ -52,7 +102,7 @@ If `run_install` is a YAML string representation of either an object or an array
### `package_json_file`
**Optional** (_type:_ `string`, _default:_ `package.json`) File path to the `package.json`/[`package.yaml`](https://github.com/pnpm/pnpm/pull/1799) to read "packageManager" configuration.
**Optional** (_type:_ `string`, _default:_ `package.json`) File path to the `package.json`/[`package.yaml`](https://github.com/pnpm/pnpm/pull/1799) to read `packageManager` or `devEngines.packageManager` configuration.
### `standalone`
@@ -74,7 +124,7 @@ Location of `pnpm` and `pnpx` command.
### Install only pnpm without `packageManager`
This works when the repo either doesn't have a `package.json` or has a `package.json` but it doesn't specify `packageManager`.
This works when the repo either doesn't have a `package.json` or has a `package.json` but it doesn't specify `packageManager` or `devEngines.packageManager`.
```yaml
on:
@@ -93,7 +143,7 @@ jobs:
### Install only pnpm with `packageManager`
Omit `version` input to use the version in the [`packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
Omit `version` input to use the version in the [`packageManager` or `devEngines.packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
```yaml
on:
@@ -158,6 +208,8 @@ jobs:
**Note:** You don't need to run `pnpm store prune` at the end; post-action has already taken care of that.
Besides the store, this also caches pnpm's lockfile verification results (pnpm v11 and newer). Repositories that configure supply-chain policies such as `minimumReleaseAge` or `trustPolicy` make pnpm check every lockfile entry against the registry on each install; that check depends only on the lockfile and the policies, so its result is cached and reused until the lockfile changes.
### Cache dependencies from multiple lockfiles
```yaml
@@ -187,7 +239,7 @@ jobs:
## Notes
This action does not setup Node.js for you, use [actions/setup-node](https://github.com/actions/setup-node) yourself.
This action does not set up Node.js. Use [actions/setup-node](https://github.com/actions/setup-node) yourself. If you are on pnpm v11 or newer, [`pnpm/setup`](https://github.com/pnpm/setup) can install pnpm and Node.js in a single step.
## License

View File

@@ -16,7 +16,10 @@ inputs:
required: false
default: 'null'
cache:
description: Whether to cache the pnpm store directory
description: |
Whether to cache the pnpm store directory and, on pnpm v11 and newer,
the results of pnpm's lockfile verification against the configured
supply-chain policies. Both are keyed on the lockfile's content hash.
required: false
default: 'false'
cache_dependency_path:

294
dist/index.js vendored

File diff suppressed because one or more lines are too long

View File

@@ -4,23 +4,38 @@ import { getExecOutput } from '@actions/exec'
import { hashFiles } from '@actions/glob'
import os from 'os'
import { Inputs } from '../inputs'
import { restoreVerificationCache } from '../lockfile-verification-cache'
export async function runRestoreCache(inputs: Inputs) {
const cachePath = await getCacheDirectory()
saveState('cache_path', cachePath)
const fileHash = await hashFiles(inputs.cacheDependencyPath)
if (!fileHash) {
throw new Error('Some specified paths were not resolved, unable to cache dependencies.')
}
await runRestoreStoreCache(fileHash)
await restoreVerificationCache(fileHash)
}
async function runRestoreStoreCache(fileHash: string) {
const cachePath = await getCacheDirectory()
saveState('cache_path', cachePath)
const primaryKey = `pnpm-cache-${process.env.RUNNER_OS}-${os.arch()}-${fileHash}`
debug(`Primary key is ${primaryKey}`)
saveState('cache_primary_key', primaryKey)
let cacheKey = await restoreCache([cachePath], primaryKey)
// We don't need to download everything again if only one dependency changed
// We can still re-use previous store to cache the rest of the unchanged dependencies
const restoreKeys = [
`pnpm-cache-${process.env.RUNNER_OS}-${os.arch()}-`
];
setOutput('cache-hit', Boolean(cacheKey))
let cacheKey = await restoreCache([cachePath], primaryKey, restoreKeys)
// A restore-key (prefix) match still restores an older store, but "cache-hit"
// must only report an exact primary-key match, so dependency installation
// is not skipped when the lockfile has changed.
setOutput('cache-hit', cacheKey === primaryKey)
if (!cacheKey) {
info(`Cache is not found`)

View File

@@ -3,6 +3,7 @@ import restoreCache from './cache-restore'
import saveCache from './cache-save'
import getInputs, { Inputs } from './inputs'
import installPnpm from './install-pnpm'
import { saveVerificationCache } from './lockfile-verification-cache'
import setOutputs from './outputs'
import pnpmInstall from './pnpm-install'
import pruneStore from './pnpm-store-prune'
@@ -32,6 +33,9 @@ async function runMain() {
async function runPost() {
const inputs = JSON.parse(getState('inputs')) as Inputs
// Saved ahead of the prune because `pnpm store prune` drops the
// verification log along with the rest of the store's derived state.
await saveVerificationCache()
pruneStore(inputs)
await saveCache(inputs)
}

View File

@@ -5,18 +5,18 @@
"packages": {
"": {
"dependencies": {
"@pnpm/exe": "11.1.1"
"@pnpm/exe": "11.19.0"
}
},
"node_modules/@pnpm/exe": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/exe/-/exe-11.1.1.tgz",
"integrity": "sha512-5mQnDW1NCBRRWA+cnGhQO+tIrfSfWm3/IyGxU88LnT+tzNW5UrwwKfjsnnYJToyAjIfdfEJtJKUxCvP+mhA+nQ==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/exe/-/exe-11.19.0.tgz",
"integrity": "sha512-P1mw8BZaNkEpttlyzKsxTj7PVs94bMB4cQ8pJhgbrCTSBP7xCzKS3VlOwIInS7aS5by6KAbfO5Vs9yK/ekugrg==",
"hasInstallScript": true,
"license": "MIT",
"dependencies": {
"@reflink/reflink": "0.1.19",
"detect-libc": "^2.0.3"
"detect-libc": "^2.1.2"
},
"bin": {
"pn": "pn",
@@ -28,19 +28,19 @@
"url": "https://opencollective.com/pnpm"
},
"optionalDependencies": {
"@pnpm/linux-arm64": "11.1.1",
"@pnpm/linux-x64": "11.1.1",
"@pnpm/linuxstatic-arm64": "11.1.1",
"@pnpm/linuxstatic-x64": "11.1.1",
"@pnpm/macos-arm64": "11.1.1",
"@pnpm/win-arm64": "11.1.1",
"@pnpm/win-x64": "11.1.1"
"@pnpm/linux-arm64": "11.19.0",
"@pnpm/linux-x64": "11.19.0",
"@pnpm/linuxstatic-arm64": "11.19.0",
"@pnpm/linuxstatic-x64": "11.19.0",
"@pnpm/macos-arm64": "11.19.0",
"@pnpm/win-arm64": "11.19.0",
"@pnpm/win-x64": "11.19.0"
}
},
"node_modules/@pnpm/linux-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linux-arm64/-/linux-arm64-11.1.1.tgz",
"integrity": "sha512-u9hs51XV0/gU5LLfNLoQsozGKIxNjxsh/0xPr+8Hny0M38psa4lBtwFvarL2bLToPIrtueQYi65LdlzRxITRyg==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/linux-arm64/-/linux-arm64-11.19.0.tgz",
"integrity": "sha512-c5AJqnsj0BMqMCOtctOzsCqyfY+afFe1kdM9F2FrNhYwtnQRMHoJy+51qfee4yuTPOVRyk3Yh1dwvyAadiznvA==",
"cpu": [
"arm64"
],
@@ -54,9 +54,9 @@
}
},
"node_modules/@pnpm/linux-x64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linux-x64/-/linux-x64-11.1.1.tgz",
"integrity": "sha512-yQO9i57oyJmIG22BjV7sqLUT2syKQohiku8yNZRgp7M6wsVkikpVLLVSpBifQnrI/P/roueKnWSUEESH1aPaoA==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/linux-x64/-/linux-x64-11.19.0.tgz",
"integrity": "sha512-KOKpA9o75SvmRQgWO+EqEpQzJg1b9uHk5y61PAx90sSpdYtKDPua2eBXBglzv8YK1xM3DsYXFEf7Scs+3HeDsA==",
"cpu": [
"x64"
],
@@ -70,9 +70,9 @@
}
},
"node_modules/@pnpm/linuxstatic-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-arm64/-/linuxstatic-arm64-11.1.1.tgz",
"integrity": "sha512-FUZB8L9Z8L5m88G0RTx5AsHFr5yUQPW+28zQdTNUWxiLwj11FW/fOLodYdcNYHdNJFepsZyqt3aRnpiqIdZb2g==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-arm64/-/linuxstatic-arm64-11.19.0.tgz",
"integrity": "sha512-Ci9WxgCInZc3F43R6BfaHevi+dYqaI5CLi6421egFsK649eHvYPytvu+zABhTNlYGNJbD8j9w+AUYInz/TPsyQ==",
"cpu": [
"arm64"
],
@@ -89,9 +89,9 @@
}
},
"node_modules/@pnpm/linuxstatic-x64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-x64/-/linuxstatic-x64-11.1.1.tgz",
"integrity": "sha512-I/z56hfa1zM5F/Unup/1NrgsA+dcptsKQ2TjJLFz3wHKDx0RLrfF7DB0Rkpnr5IoAZ33v0GFZjlGhkOtc9VFGw==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-x64/-/linuxstatic-x64-11.19.0.tgz",
"integrity": "sha512-GNMk96vNJ4uEWigekarjHofXNDFsTYRL0Mw2YlDkv/W+u0cn/UAVPHfd5aAfsf6Arel2ZQfxPUTXlpunFujWnA==",
"cpu": [
"x64"
],
@@ -108,9 +108,9 @@
}
},
"node_modules/@pnpm/macos-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/macos-arm64/-/macos-arm64-11.1.1.tgz",
"integrity": "sha512-YQu6fC27F4jTIpXhF+4PdzOV7uSnVVG9KUxj5W+AFj0XFlUvBw+I1NsoPCY6uV1nccxWpIAZOTZtSj8+hWPb8w==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/macos-arm64/-/macos-arm64-11.19.0.tgz",
"integrity": "sha512-I3Ee/GQlPxEOeBSzqxBNwcTHxVebjMiN2xLdTBS6OK2TAPzbWMIExjU5brxhr8rAk73p7mbv/a/2tFC/3gl6FA==",
"cpu": [
"arm64"
],
@@ -124,9 +124,9 @@
}
},
"node_modules/@pnpm/win-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/win-arm64/-/win-arm64-11.1.1.tgz",
"integrity": "sha512-2HvZut3IcKPxzIfOjBJ4677PaLIh57mWccL86O+q71QhO5emnQvht0CE19IoEyUIOEe1WjlN+Su/dD5k6CuGyg==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/win-arm64/-/win-arm64-11.19.0.tgz",
"integrity": "sha512-rOiWuJ9wjaFY9ZDVPGVjpvjIQHZNB72rioxvuyzDKJ7dqKQ97VF27a4rmOtjhMB5u83cdDGEJ+OY+H1+TP+frw==",
"cpu": [
"arm64"
],
@@ -140,9 +140,9 @@
}
},
"node_modules/@pnpm/win-x64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/win-x64/-/win-x64-11.1.1.tgz",
"integrity": "sha512-QXBIBErgPhGLovOVzTRIpHsejFKebyqlcF3fea/TfH87gkhN5yWH0WuTPRBoOWvpk6aNhjDW4RPUMx8RaPqxjw==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/@pnpm/win-x64/-/win-x64-11.19.0.tgz",
"integrity": "sha512-l26XeTxoGxfU+mVcZ5jFdP9hNe5yrOlLPSkAlwwpXPI1iyyU4JUSxm6Jdyxu1UAU1FerD/BvLK2vrlR6d9ogag==",
"cpu": [
"x64"
],

View File

@@ -5,13 +5,13 @@
"packages": {
"": {
"dependencies": {
"pnpm": "11.1.1"
"pnpm": "11.19.0"
}
},
"node_modules/pnpm": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/pnpm/-/pnpm-11.1.1.tgz",
"integrity": "sha512-0f319zxhe2T6GlaoHDyN/g6WbjOmAQqiVrUXrne+Idk+Ba/8DeGoOw5PKdVp9otEaujwaM1yR8C7PfD7TXvfmg==",
"version": "11.19.0",
"resolved": "https://registry.npmjs.org/pnpm/-/pnpm-11.19.0.tgz",
"integrity": "sha512-eIHz7VkNRyxKlV4riLISF5ERYGbcyIy8o4SeybYPG7qm0syyIfqR2k4cZb7yvL43k2Wup6xTnHv4be3DobItzg==",
"license": "MIT",
"bin": {
"pn": "bin/pnpm.mjs",

View File

@@ -0,0 +1,95 @@
import { restoreCache, saveCache } from '@actions/cache'
import { debug, getState, info, saveState, warning } from '@actions/core'
import { getExecOutput } from '@actions/exec'
import { existsSync } from 'fs'
import os from 'os'
import path from 'path'
import { removeWindowsExtendedPathPrefix } from '../windows-path'
/**
* pnpm v11+ verifies every lockfile entry against the configured
* supply-chain policies (`minimumReleaseAge`, `trustPolicy`, …) and memoizes
* the verdict in this file, so the next install with the same lockfile and
* the same policies skips the registry round-trips entirely. Without it a CI
* job re-verifies the whole lockfile on every run, which on a large
* repository costs more than the install itself.
*/
const VERIFICATION_CACHE_FILE = 'lockfile-verified.jsonl'
const PATH_STATE = 'lockfile_verification_cache_path'
const KEY_STATE = 'lockfile_verification_cache_key'
const RESTORED_STATE = 'lockfile_verification_cache_restored'
/**
* The verdict is only valid for the exact lockfile content it was recorded
* for, so this cache is keyed on the same lockfile hash as the store cache
* but restored without prefix fallback: an older entry could never be used.
*/
export async function restoreVerificationCache(lockfileHash: string): Promise<void> {
try {
const cacheFilePath = path.join(await getPnpmCacheDirectory(), VERIFICATION_CACHE_FILE)
const key = `pnpm-lockfile-verified-${process.env.RUNNER_OS}-${os.arch()}-${lockfileHash}`
saveState(PATH_STATE, cacheFilePath)
saveState(KEY_STATE, key)
debug(`Lockfile verification cache path is ${cacheFilePath}, key is ${key}`)
const restoredKey = await restoreCache([cacheFilePath], key)
if (!restoredKey) {
info('Lockfile verification cache is not found')
return
}
saveState(RESTORED_STATE, 'true')
info(`Lockfile verification cache restored from key: ${restoredKey}`)
} catch (error) {
// The gate only costs time, never correctness — a job that cannot reuse
// a past verdict re-verifies and moves on.
warning(`Failed to restore the lockfile verification cache: ${(error as Error).message}`)
}
}
export async function saveVerificationCache(): Promise<void> {
if (getState(RESTORED_STATE) === 'true') return
const cacheFilePath = getState(PATH_STATE)
const key = getState(KEY_STATE)
if (!cacheFilePath || !key || !existsSync(cacheFilePath)) return
try {
const cacheId = await saveCache([cacheFilePath], key)
if (cacheId === -1) return
info(`Lockfile verification cache saved with the key: ${key}`)
} catch (error) {
warning(`Failed to save the lockfile verification cache: ${(error as Error).message}`)
}
}
async function getPnpmCacheDirectory(): Promise<string> {
const { stdout } = await getExecOutput('pnpm config get cacheDir', undefined, {
silent: true,
ignoreReturnCode: true,
})
const configured = stdout.trim()
// `pnpm config get` reports settings, not defaults: an unset `cacheDir`
// prints `undefined` and the default has to be derived here.
if (configured && configured !== 'undefined') {
return removeWindowsExtendedPathPrefix(configured)
}
return defaultPnpmCacheDirectory()
}
/** Mirrors pnpm's own `cacheDir` default. */
function defaultPnpmCacheDirectory(): string {
const { XDG_CACHE_HOME, LOCALAPPDATA } = process.env
if (XDG_CACHE_HOME) return path.join(XDG_CACHE_HOME, 'pnpm')
const homeDir = os.homedir()
switch (process.platform) {
case 'darwin':
return path.join(homeDir, 'Library', 'Caches', 'pnpm')
case 'win32':
return LOCALAPPDATA ? path.join(LOCALAPPDATA, 'pnpm-cache') : path.join(homeDir, '.pnpm-cache')
default:
return path.join(homeDir, '.cache', 'pnpm')
}
}

19
src/windows-path/index.ts Normal file
View File

@@ -0,0 +1,19 @@
/**
* pnpm may report an extended-length path on Windows. The `?` in that prefix
* is interpreted as a wildcard by `@actions/cache`, which rejects it as a glob
* in the root segment. Cache APIs do not need the extended-length form, so
* convert it back to a regular drive or UNC path.
*/
export function removeWindowsExtendedPathPrefix(cachePath: string): string {
const extendedPathPrefix = '\\\\?\\'
if (!cachePath.startsWith(extendedPathPrefix)) return cachePath
const pathWithoutPrefix = cachePath.slice(extendedPathPrefix.length)
const uncPrefix = 'UNC\\'
if (pathWithoutPrefix.toUpperCase().startsWith(uncPrefix)) {
return `\\\\${pathWithoutPrefix.slice(uncPrefix.length)}`
}
return pathWithoutPrefix
}
export default removeWindowsExtendedPathPrefix