RehanAhmad25 opened a new pull request, #72311:
URL: https://github.com/apache/airflow/pull/72311

   <!-- SPDX-License-Identifier: Apache-2.0
         https://www.apache.org/licenses/LICENSE-2.0 -->
   
   Picks up the third item from the follow-up checklist on #72298 : a prek 
check that compares each UI workspace's `pnpm.overrides` (package.json) against 
the `overrides:` block pnpm mirrors into that workspace's pnpm-lock.yaml, and 
fails with a clear message naming the exact keys that drifted, instead of 
surfacing as `ERR_PNPM_LOCKFILE_CONFIG_MISMATCH` deep in a hook log.
   
   This does not fix the underlying issue. It doesn't identify why dependabot 
drops the block on some updates (checklist item 1) and doesn't implement a 
durable fix (item 2). A grouped dependabot PR that hits the bug will still fail 
static checks and still need a human to regenerate the lockfile , this only 
makes that failure legible instead of cryptic. Leaving 1 and 2 open for
   separate discussion.
   
   While testing this against `main`, the check caught a pre-existing drift: 
`providers/fab/.../www/pnpm-lock.yaml` carries a `moment-timezone` override 
that was missing from `package.json`'s `pnpm.overrides` (leftover from an old
   yarn `resolutions` setup, before this workspace moved to pnpm). Fixed that 
in this PR since the new check would otherwise fail on `main` immediately.
   
   related: #72298
   
   ---
   ##### Was generative AI tooling used to co-author this PR?
   - [X] Yes (Claude)
   <!--
   Generated-by: Claude following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   -->
   ---
   * Read the **[Pull Request 
Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)**
 for more information. Note: commit author/co-author name and email in commits 
become permanently public when merged.
   * For fundamental code changes, an Airflow Improvement Proposal 
([AIP](https://cwiki.apache.org/confluence/display/AIRFLOW/Airflow+Improvement+Proposals))
 is needed.
   * When adding dependency, check compliance with the [ASF 3rd Party License 
Policy](https://www.apache.org/legal/resolved.html#category-x).
   * For significant user-facing changes create newsfragment: 
`{pr_number}.significant.rst`, in 
[airflow-core/newsfragments](https://github.com/apache/airflow/tree/main/airflow-core/newsfragments).
 You can add this file in a follow-up commit after the PR is created so you 
know the PR number.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to