docs(agents): note that lockfile re-resolution moves the Studio next overrides - #2038
Conversation
…overrides Editing overrides, `pnpm update <pkg>` or `pnpm dedupe` makes pnpm fully re-resolve, and it cannot reuse a locked version for the `next` dist-tag overrides, so a targeted dependency change silently upgrades the Studio prerelease (and can trip `trustPolicy: no-downgrade`). Document how to keep it out, and why a temporary exact-version pin is not a clean alternative.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
|
✅ E2E Tests🟢 43 passed • 🟡 1 flaky • view full report • view run Studio: https://plugins-e2e-test-studio-mnndn9nh5.sanity.dev Datasets: |
Coverage Report
File CoverageNo changed files found. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The documentation accurately reflects the configured overrides and provides relevant safeguards.
Review effort: Balanced
Findings: None
What changed in this PR
Documents a pnpm lockfile re-resolution pitfall affecting Studio next overrides.
Changes:
- Explains when Studio prereleases may be unintentionally upgraded.
- Documents safe handling and verification steps.
| File | Description |
|---|---|
AGENTS.md |
Adds lockfile re-resolution guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Description
Follow-up to #2034. #2034 was merged before this AGENTS.md commit was pushed, so it lands separately.
While
pnpm-workspace.yamloverridessanity,@sanity/mutator,@sanity/schema,@sanity/types,@sanity/util,@sanity/vision, andgroqto thenextdist-tag, any full re-resolution moves them to the newestnextprerelease. That includes editingoverrides,pnpm update <pkg>, andpnpm dedupe. pnpm cannot reuse a locked version for a dist-tag, so a targeted dependency change silently becomes a Studio upgrade. The new prerelease can also triptrustPolicy: no-downgrade, which is what happened with@sanity/sdk@3.5.0until #2037 allowlisted it.The note covers the two options: call the Studio bump out in the PR, or keep it out by resolving through a local registry proxy that serves the locked versions as
next. #2034's lockfile was produced the second way. The note also warns against temporarily pinning the overrides to an exact version. I tried that first: pnpm applies semver overrides topeerDependenciesranges too, and the rewritten ranges (for examplesanity: 6.13.3-next.7in@sanity/cli-build's peers) stay in the lockfile.What to review
AGENTS.md: one new paragraph under "Code Style → Dependencies", after the Studio upgrade steps.Testing
Docs only.
oxfmt --check AGENTS.mdpasses.Notes for release
N/A. Docs only, no changeset.