Skip to content

docs(agents): note that lockfile re-resolution moves the Studio next overrides - #2038

Merged
stipsan merged 1 commit into
mainfrom
cody/agents-next-overrides-note-80eb
Sep 28, 2026
Merged

stipsan merged 1 commit into
mainfrom
cody/agents-next-overrides-note-80eb

Conversation

@stipsan

@stipsan stipsan commented Sep 28, 2026

Copy link
Copy Markdown
Member

Description

Follow-up to #2034. #2034 was merged before this AGENTS.md commit was pushed, so it lands separately.

While pnpm-workspace.yaml overrides sanity, @sanity/mutator, @sanity/schema, @sanity/types, @sanity/util, @sanity/vision, and groq to the next dist-tag, any full re-resolution moves them to the newest next prerelease. That includes editing overrides, pnpm update <pkg>, and pnpm dedupe. pnpm cannot reuse a locked version for a dist-tag, so a targeted dependency change silently becomes a Studio upgrade. The new prerelease can also trip trustPolicy: no-downgrade, which is what happened with @sanity/sdk@3.5.0 until #2037 allowlisted it.

The note covers the two options: call the Studio bump out in the PR, or keep it out by resolving through a local registry proxy that serves the locked versions as next. #2034's lockfile was produced the second way. The note also warns against temporarily pinning the overrides to an exact version. I tried that first: pnpm applies semver overrides to peerDependencies ranges too, and the rewritten ranges (for example sanity: 6.13.3-next.7 in @sanity/cli-build's peers) stay in the lockfile.

What to review

  • AGENTS.md: one new paragraph under "Code Style → Dependencies", after the Studio upgrade steps.

Testing

Docs only. oxfmt --check AGENTS.md passes.

Notes for release

N/A. Docs only, no changeset.

Open in Web Open in Cursor 

…overrides

Editing overrides, `pnpm update <pkg>` or `pnpm dedupe` makes pnpm fully re-resolve,
and it cannot reuse a locked version for the `next` dist-tag overrides, so a targeted
dependency change silently upgrades the Studio prerelease (and can trip
`trustPolicy: no-downgrade`). Document how to keep it out, and why a temporary
exact-version pin is not a clean alternative.
@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
plugins-studio Ready Ready Preview Sep 28, 2026 2:31pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
plugins-e2e-test-studio Ignored Ignored Sep 28, 2026 2:31pm UTC

Request Review

@changeset-bot

changeset-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: c374637

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ E2E Tests

🟢 43 passed • 🟡 1 flaky • view full report • view run

Studio: https://plugins-e2e-test-studio-mnndn9nh5.sanity.dev

Datasets: pr-2038-chromium-36436598085, pr-2038-firefox-36436598085

@github-actions

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 33.34% 5810 / 17426
🔵 Statements 33.11% 6142 / 18545
🔵 Functions 29.43% 1535 / 5214
🔵 Branches 24.55% 3014 / 12272
File CoverageNo changed files found.
Generated in workflow #10124 for commit c374637 by the Vitest Coverage Report Action

@stipsan
stipsan marked this pull request as ready for review September 28, 2026 15:41
@stipsan
stipsan requested a review from a team as a code owner September 28, 2026 15:41
@stipsan
stipsan requested review from bjoerge and a balanced review from Copilot and removed request for a team September 28, 2026 15:41
@stipsan
stipsan merged commit a99ceac into main Sep 28, 2026
26 checks passed
@stipsan
stipsan deleted the cody/agents-next-overrides-note-80eb branch September 28, 2026 15:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation accurately reflects the configured overrides and provides relevant safeguards.

Review effort: Balanced
Findings: None

What changed in this PR

Documents a pnpm lockfile re-resolution pitfall affecting Studio next overrides.

Changes:

  • Explains when Studio prereleases may be unintentionally upgraded.
  • Documents safe handling and verification steps.
File Description
AGENTS.md Adds lockfile re-resolution guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch was successfully deployed

1 active deployment
Preview – plugins-studio — c3746371 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants