Skip to content

chore(deps): bump pnpm/action-setup from 3 to 4#8

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/pnpm/action-setup-4
Closed

chore(deps): bump pnpm/action-setup from 3 to 4#8
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/pnpm/action-setup-4

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Mar 5, 2026

Bumps pnpm/action-setup from 3 to 4.

Release notes

Sourced from pnpm/action-setup's releases.

v4.0.0

An error is thrown if one version of pnpm is specified in the packageManager field of package.json and a different version is specified in the action's settings #122

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Upgrade CI to use pnpm/action-setup v4 across all jobs. This keeps our pnpm setup current and adds strict version checks.

  • Migration
    • v4 fails if the pnpm version in packageManager differs from the action input. We set version: 10; ensure packageManager specifies pnpm@10 or update the input to match.

Written for commit 2af1149. Summary will update on new commits.

Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 3 to 4.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@v3...v4)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 5, 2026
Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 1 file

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name=".github/workflows/ci.yml">

<violation number="1" location=".github/workflows/ci.yml:22">
P1: Potential CI breakage: `pnpm/action-setup@v4` will error if `version` doesn't match the `packageManager` field in `package.json` (`pnpm@10.28.2`). Since `version: 10` resolves to the latest 10.x, this may trigger the new version mismatch check. With v4, you can remove `version` entirely — the action reads from `packageManager` in `package.json` automatically.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

Comment thread .github/workflows/ci.yml
@@ -19,7 +19,7 @@ jobs:
uses: actions/checkout@v4
Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai Bot Mar 5, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Potential CI breakage: pnpm/action-setup@v4 will error if version doesn't match the packageManager field in package.json (pnpm@10.28.2). Since version: 10 resolves to the latest 10.x, this may trigger the new version mismatch check. With v4, you can remove version entirely — the action reads from packageManager in package.json automatically.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/ci.yml, line 22:

<comment>Potential CI breakage: `pnpm/action-setup@v4` will error if `version` doesn't match the `packageManager` field in `package.json` (`pnpm@10.28.2`). Since `version: 10` resolves to the latest 10.x, this may trigger the new version mismatch check. With v4, you can remove `version` entirely — the action reads from `packageManager` in `package.json` automatically.</comment>

<file context>
@@ -19,7 +19,7 @@ jobs:
 
       - name: Setup pnpm
-        uses: pnpm/action-setup@v3
+        uses: pnpm/action-setup@v4
         with:
           version: 10
</file context>
Suggested change
uses: actions/checkout@v4
uses: pnpm/action-setup@v4
Fix with Cubic

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Mar 19, 2026

Superseded by #26.

@dependabot dependabot Bot closed this Mar 19, 2026
@dependabot dependabot Bot deleted the dependabot/github_actions/pnpm/action-setup-4 branch March 19, 2026 22:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants