The js-deps stage installed ESLint and prettier with yarn 1, the one the node image ships. yarn 1 is no longer developed, and node printed its url.parse() deprecation warning during every uncached install.
package.json now pins yarn 4.18.1 by version and hash in its packageManager field. The js-deps stage runs corepack enable yarn, using the node image's own corepack, which fetches that yarn and checks it against the hash. It then runs yarn install --immutable. --mode=skip-build takes the place of the old --ignore-scripts.
yarn.lock was regenerated in yarn 4's format by migrating the old lockfile, so every package keeps the version it was locked at; ESLint and prettier stay at 10.11.0 and 3.9.9. The new .yarnrc.yml keeps the install in node_modules/. yarn 4's default layout has no node_modules/.bin, which the lint and Markdown stages run the tools from. Adding .yarnrc.yml to the stage's COPY means a change to it also re-runs the install.
The Dockerfile comment above the stage and the README's Linting and Docker sections now describe the corepack install and name the three files that decide when it re-runs.
The hash is the sha512 of yarn 4.18.1's released yarn.js, which is what corepack checks; it does not match the npm tarball's integrity value.
Judgement call: yarn 4's telemetry stays at its default. yarn sends nothing on its first run, and every install starts in a fresh layer.
Model: opus-5-5
The `js-deps` stage installed ESLint and prettier with yarn 1, the one the node image ships. yarn 1 is no longer developed, and node printed its `url.parse()` deprecation warning during every uncached install.
`package.json` now pins yarn 4.18.1 by version and hash in its `packageManager` field. The `js-deps` stage runs `corepack enable yarn`, using the node image's own corepack, which fetches that yarn and checks it against the hash. It then runs `yarn install --immutable`. `--mode=skip-build` takes the place of the old `--ignore-scripts`.
`yarn.lock` was regenerated in yarn 4's format by migrating the old lockfile, so every package keeps the version it was locked at; ESLint and prettier stay at 10.11.0 and 3.9.9. The new `.yarnrc.yml` keeps the install in `node_modules/`. yarn 4's default layout has no `node_modules/.bin`, which the lint and Markdown stages run the tools from. Adding `.yarnrc.yml` to the stage's `COPY` means a change to it also re-runs the install.
The `Dockerfile` comment above the stage and the README's Linting and Docker sections now describe the corepack install and name the three files that decide when it re-runs.
The hash is the sha512 of yarn 4.18.1's released `yarn.js`, which is what corepack checks; it does not match the npm tarball's integrity value.
Judgement call: yarn 4's telemetry stays at its default. yarn sends nothing on its first run, and every install starts in a fresh layer.
Model: opus-5-5
yarn 1, which the node image ships and which is no longer developed,
printed node's url.parse() deprecation warning during the js-deps
install. package.json now pins yarn 4.18.1 by version and hash in its
packageManager field; the js-deps stage enables it with the node
image's own corepack and runs `yarn install --immutable`. yarn.lock is
regenerated in yarn 4's format from the old lockfile, so every package
keeps the version it had. The new .yarnrc.yml keeps the install in
node_modules/, where the lint and Markdown stages run the tools from.
Model: opus-5-5
Review passed: this change meets the definition of done for #493 and is ready to merge into next.
Model: opus-5-5
Review passed: this change meets the definition of done for https://git.eeqj.de/sneak/webhooker/issues/493 and is ready to merge into `next`.
Model: opus-5-5
clawbot
merged commit fe5e0d4173 into next2026-10-03 07:03:32 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The
js-depsstage installed ESLint and prettier with yarn 1, the one the node image ships. yarn 1 is no longer developed, and node printed itsurl.parse()deprecation warning during every uncached install.package.jsonnow pins yarn 4.18.1 by version and hash in itspackageManagerfield. Thejs-depsstage runscorepack enable yarn, using the node image's own corepack, which fetches that yarn and checks it against the hash. It then runsyarn install --immutable.--mode=skip-buildtakes the place of the old--ignore-scripts.yarn.lockwas regenerated in yarn 4's format by migrating the old lockfile, so every package keeps the version it was locked at; ESLint and prettier stay at 10.11.0 and 3.9.9. The new.yarnrc.ymlkeeps the install innode_modules/. yarn 4's default layout has nonode_modules/.bin, which the lint and Markdown stages run the tools from. Adding.yarnrc.ymlto the stage'sCOPYmeans a change to it also re-runs the install.The
Dockerfilecomment above the stage and the README's Linting and Docker sections now describe the corepack install and name the three files that decide when it re-runs.The hash is the sha512 of yarn 4.18.1's released
yarn.js, which is what corepack checks; it does not match the npm tarball's integrity value.Judgement call: yarn 4's telemetry stays at its default. yarn sends nothing on its first run, and every install starts in a fresh layer.
Model: opus-5-5
Review passed: this change meets the definition of done for #493 and is ready to merge into
next.Model: opus-5-5