lockfile-lint doesn't support pnpm-lock.yaml. pnpm enforces tarball
integrity hashes on install, covering the core supply-chain concern.
The explicit allowlists (hosts, schemes, git URLs) are gone with it;
acceptable tradeoff for now.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
eslint-plugin-react-hooks bumped from 7.0.1 to 7.1.1 under pnpm resolution,
which tightened preserve-manual-memoization.
Real fixes:
- RichTextTag: correct typo'd optional chain in deps array
- ContentHider: match post-guard narrowing in deps array
- ProfileHoverCard: add (stable) dispatch to deps arrays
Bulk-suppress the remaining 6 cases where the compiler can't preserve
memoization across a memo boundary; those need real refactors, follow-up.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- switch root package manager to pnpm 10.33.4 via packageManager field
- add .npmrc with node-linker=hoisted for RN/Expo compatibility
- convert yarn resolutions to pnpm.overrides; pin psl@1.9.0 and @types/psl@1.1.1
to keep types resolving under exports-aware resolution
- pin react-compiler-runtime and babel-plugin-react-compiler to real rc.3 (the
deprecated "Wrong version name was published" tag would otherwise resolve)
- add pnpm.onlyBuiltDependencies allowlist for @sentry/cli, core-js-pure,
esbuild, unrs-resolver
- regenerate pnpm-lock.yaml; delete yarn.lock; drop postinstall-postinstall
- update all workflows, Dockerfile, Dockerfile.embedr (root-level), Makefile,
conductor.json; bskyembed/bskylink/bskyogcard/dev-env stay on yarn
- update docs (CLAUDE.md, docs/build.md, docs/testing.md, docs/localization.md,
bskyweb/README.md, scripts/push-notification/README.md, BlueskyClip/README.md)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>