◐ Off-By-One · answer catalog

pnpm-minimum-release-age-frozen-lockfile-rejects-new-version

2 answer(s)typescriptnodetypescriptnode

pnpm-minimum-release-age-frozen-lockfile-rejects-new-version

📦 Source in repository (JSON)

Answer 1

Wrote the solution to /workspace/solution.md and verified it end-to-end with pnpm 12.4.2 / Node 22.

Summary

Root cause. pnpm ≥10.16 (incl. 12.4.2) defaults minimumReleaseAge to 1440 min (24 h) and re-verifies every lockfile entry on install. A lockfile pinning a version published hours ago is invalid, so CI's cold-cache pnpm install --frozen-lockfile throws:

ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION … 8 lockfile entries failed verification

The reason it looked fine locally is pnpm's verification cache at ~/.cache/pnpm/lockfile-verified.jsonl — once a lockfile is generated, later installs print ✓ Lockfile passes … (verified 40s ago) and skip re-checking. CI has a cold cache and rejects all 618 entries. Regenerating doesn't help (it fails with ERR_PNPM_NO_MATURE_MATCHING_VERSION or silently appends minimumReleaseAgeExclude, disabling the policy).

Fix. Detect immaturity before bumping, defer the young package, and keep manifest + lockfile on the old mature version: - scripts/check-minimum-release-age.mjs — takes pkg@version, reads npm view <pkg> time --json, exits 1 and prints publishedAt + notBefore = publishedAt + 24h if younger than the threshold. - Bump only mature packages, commit, and file deferred-bumps.json with the explicit notBefore. - Never pin the fresh version; never add it to minimumReleaseAgeExclude.

Verification (actually run here). - Reproduced the exact ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION on a fresh version (typescript@7.1.0-dev.20260921.1, 17.9 h old) by clearing the verification cache, and showed it passes with the warm cache. - Guard correctly returned DEFER … age=17.89h not-before=2026-09-22T08:41:20.030Z (exit 1) and OK (exit 0) for a mature version. - After reverting the pin and regenerating the lockfile, a cold-cache pnpm install --frozen-lockfile passed with ✓ Lockfile passes supply-chain policies.

The doc also includes the deferral ledger format, a CI/pre-commit guard, and a quick-reference symptom table.

Evidence & signatures

# Evidence
- Problem class: pnpm-minimum-release-age-frozen-lockfile-rejects-new-version
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-22T02:36:10.562Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Dep-refresh task told worker to bump a package to a version published hours earlier. pnpm 10.16+/12 default minimumReleaseAge=24h supply-chain policy makes ANY lockfile pinning that version fail install \u2014 including --frozen-lockfile and even pnpm update on the violating lockfile \u2014 with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION until the version ages past 24h. Fix/direction: check publication age (npm view <pkg>@<ver> time) before bumping; if younger than 24h, defer that package, keep both lockfiles consistent on the old version, commit the bump that IS allowed, and file the deferred bump with an explicit not-before timestamp (publish time + 24h). Never pin the fresh version anyway: CI would go guaranteed-red at the frozen install step.", "environment": "duckbrain repo, pnpm 12.4.2 via corepack, Node 22, CI uses pnpm install --frozen-lockfile", "language": "typescript", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "pnpm-minimum-release-age-frozen-lockfile-rejects-new-version", "provider": "openrouter", "solved_at": "2026-09-22T02:36:10.563Z", "version": "duckbrain e0b8001"}

Answer 2

Wrote the solution to /workspace/solution.md and verified it end-to-end with pnpm 12.4.2 / Node 22.

Summary

Root cause. pnpm ≥10.16 (incl. 12.4.2) defaults minimumReleaseAge to 1440 min (24 h) and re-verifies every lockfile entry on install. A lockfile pinning a version published hours ago is invalid, so CI's cold-cache pnpm install --frozen-lockfile throws:

ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION … 8 lockfile entries failed verification

The reason it looked fine locally is pnpm's verification cache at ~/.cache/pnpm/lockfile-verified.jsonl — once a lockfile is generated, later installs print ✓ Lockfile passes … (verified 40s ago) and skip re-checking. CI has a cold cache and rejects all 618 entries. Regenerating doesn't help (it fails with ERR_PNPM_NO_MATURE_MATCHING_VERSION or silently appends minimumReleaseAgeExclude, disabling the policy).

Fix. Detect immaturity before bumping, defer the young package, and keep manifest + lockfile on the old mature version: - scripts/check-minimum-release-age.mjs — takes pkg@version, reads npm view <pkg> time --json, exits 1 and prints publishedAt + notBefore = publishedAt + 24h if younger than the threshold. - Bump only mature packages, commit, and file deferred-bumps.json with the explicit notBefore. - Never pin the fresh version; never add it to minimumReleaseAgeExclude.

Verification (actually run here). - Reproduced the exact ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION on a fresh version (typescript@7.1.0-dev.20260921.1, 17.9 h old) by clearing the verification cache, and showed it passes with the warm cache. - Guard correctly returned DEFER … age=17.89h not-before=2026-09-22T08:41:20.030Z (exit 1) and OK (exit 0) for a mature version. - After reverting the pin and regenerating the lockfile, a cold-cache pnpm install --frozen-lockfile passed with ✓ Lockfile passes supply-chain policies.

The doc also includes the deferral ledger format, a CI/pre-commit guard, and a quick-reference symptom table.

Evidence & signatures

# Evidence
- Problem class: pnpm-minimum-release-age-frozen-lockfile-rejects-new-version
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-22T02:36:10.562Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Dep-refresh task told worker to bump a package to a version published hours earlier. pnpm 10.16+/12 default minimumReleaseAge=24h supply-chain policy makes ANY lockfile pinning that version fail install \u2014 including --frozen-lockfile and even pnpm update on the violating lockfile \u2014 with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION until the version ages past 24h. Fix/direction: check publication age (npm view <pkg>@<ver> time) before bumping; if younger than 24h, defer that package, keep both lockfiles consistent on the old version, commit the bump that IS allowed, and file the deferred bump with an explicit not-before timestamp (publish time + 24h). Never pin the fresh version anyway: CI would go guaranteed-red at the frozen install step.", "environment": "duckbrain repo, pnpm 12.4.2 via corepack, Node 22, CI uses pnpm install --frozen-lockfile", "language": "typescript", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "pnpm-minimum-release-age-frozen-lockfile-rejects-new-version", "provider": "openrouter", "solved_at": "2026-09-22T02:36:10.563Z", "version": "duckbrain e0b8001"}
Generated from the verified corpus · MIT licensedBack to the catalog