Docker web stage omits pnpm-workspace.yaml; image build broken #176

Closed
opened 2026-09-06 16:48:16 +00:00 by crueber · 3 comments
Owner

Docker web stage omits pnpm-workspace.yaml: image build broken by release-age policy

docker build fails at pnpm install --frozen-lockfile: ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION for dompurify@3.4.15 (published today, within the cutoff).

Root cause: Dockerfile web stage COPYs only web/package.json + web/pnpm-lock.yaml before install — not web/pnpm-workspace.yaml, which carries both allowBuilds: {esbuild: true} and the minimumReleaseAgeExclude: [dompurify@3.4.15] added in #174. The dev workspace passes; the image build doesn't.

Fix

COPY web/pnpm-workspace.yaml ./ alongside package.json/lock in the Dockerfile web stage (before install). Verify docker build goes green end to end.

Acceptance criteria

  • docker build . succeeds from a clean tree (web stage installs + builds, Go embeds dist).
  • No change to dependency set (same frozen lockfile); go vet/tests unaffected.
# Docker web stage omits pnpm-workspace.yaml: image build broken by release-age policy `docker build` fails at `pnpm install --frozen-lockfile`: `ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION` for `dompurify@3.4.15` (published today, within the cutoff). Root cause: `Dockerfile` web stage `COPY`s only `web/package.json` + `web/pnpm-lock.yaml` before install — not `web/pnpm-workspace.yaml`, which carries both `allowBuilds: {esbuild: true}` and the `minimumReleaseAgeExclude: [dompurify@3.4.15]` added in #174. The dev workspace passes; the image build doesn't. ## Fix `COPY web/pnpm-workspace.yaml ./` alongside package.json/lock in the Dockerfile web stage (before install). Verify `docker build` goes green end to end. ## Acceptance criteria - [ ] `docker build .` succeeds from a clean tree (web stage installs + builds, Go embeds dist). - [ ] No change to dependency set (same frozen lockfile); `go vet`/tests unaffected.
Author
Owner

Fixed by #177 (branch fix/issue-176): the Dockerfile web stage now COPYs web/pnpm-workspace.yaml alongside package.json/lock before install. Full docker build verified green end to end (web install + vite/SDK build, Go embed of dist → walhub:fix176).

Fixed by #177 (branch fix/issue-176): the Dockerfile web stage now COPYs web/pnpm-workspace.yaml alongside package.json/lock before install. Full docker build verified green end to end (web install + vite/SDK build, Go embed of dist → walhub:fix176).
Author
Owner

Review of PR #177 (fix/issue-176):

  1. Diff is exactly the one COPY line (main...origin/fix/issue-176, 1 file, +1/-1): COPY web/package.json web/pnpm-lock.yaml ./ -> COPY web/package.json web/pnpm-lock.yaml web/pnpm-workspace.yaml ./. No other changes.
  2. Workspace file verified (origin/fix/issue-176:web/pnpm-workspace.yaml): allowBuilds: { esbuild: true } + minimumReleaseAgeExclude: [dompurify@3.4.15] — the #174 supply-chain policy the web-stage install was missing.
  3. Layer-cache sane: pre-install COPY still keyed on the lockfile, so lockfile changes invalidate as before; the added workspace file only adds a cache-bust when IT changes. Acceptable.
  4. No secrets/certs introduced — workspace file is two policy keys, diff touches only the Dockerfile COPY.
  5. Acceptance docker build from scratch worktree at origin/fix/issue-176 (3a41644): GREEN end to end, verified twice — cached build exported walhub:fix176-review, then full --no-cache rebuild exported cleanly. Uncached log: pnpm install 'Verifying lockfile against supply-chain policies (163 entries)... Lockfile passes supply-chain policies', vite build (123 modules) + esbuild SDK bundle (dist/repos.js 27.8kb), dist/index.html + dist/repos.js checks pass, Go static build + runtime image export OK. Scratch worktree and review images removed afterward.
    Main worktree left untouched (main @6810964; only pre-existing untracked .opencode/).

MERGE RECOMMENDATION: ready to merge.

Review of PR #177 (fix/issue-176): 1. Diff is exactly the one COPY line (main...origin/fix/issue-176, 1 file, +1/-1): COPY web/package.json web/pnpm-lock.yaml ./ -> COPY web/package.json web/pnpm-lock.yaml web/pnpm-workspace.yaml ./. No other changes. 2. Workspace file verified (origin/fix/issue-176:web/pnpm-workspace.yaml): allowBuilds: { esbuild: true } + minimumReleaseAgeExclude: [dompurify@3.4.15] — the #174 supply-chain policy the web-stage install was missing. 3. Layer-cache sane: pre-install COPY still keyed on the lockfile, so lockfile changes invalidate as before; the added workspace file only adds a cache-bust when IT changes. Acceptable. 4. No secrets/certs introduced — workspace file is two policy keys, diff touches only the Dockerfile COPY. 5. Acceptance docker build from scratch worktree at origin/fix/issue-176 (3a41644): GREEN end to end, verified twice — cached build exported walhub:fix176-review, then full --no-cache rebuild exported cleanly. Uncached log: pnpm install 'Verifying lockfile against supply-chain policies (163 entries)... Lockfile passes supply-chain policies', vite build (123 modules) + esbuild SDK bundle (dist/repos.js 27.8kb), dist/index.html + dist/repos.js checks pass, Go static build + runtime image export OK. Scratch worktree and review images removed afterward. Main worktree left untouched (main @6810964; only pre-existing untracked .opencode/). MERGE RECOMMENDATION: ready to merge.
Author
Owner

Fixed by PR #177 (review: one-line COPY verified + full --no-cache docker build green), merged. Closing.

Fixed by PR #177 (review: one-line COPY verified + full --no-cache docker build green), merged. Closing.
crueber added this to the v1 milestone 2026-09-10 22:27:16 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
crueber/walhub#176
No description provided.