Files
orca/pnpm-workspace.yaml
T
Merge Sim 859a24a678 test(claude): pin @anthropic-ai/claude-agent-sdk 0.3.251 contracts against a scripted CLI
PR 1 of the SDK migration: dependency + test-only harness, no product wiring.

- Pin @anthropic-ai/claude-agent-sdk to exactly 0.3.251 — not the newest
  release — because 0.3.251 (published 2026-08-28) clears the repo's 3-day
  minimumReleaseAge supply-chain gate with no exclusion, while the newest
  release was minutes old and would have required excluding a brand-new
  publish from the exact control built to catch brand-new malicious
  publishes. Every contract this design depends on was verified identical
  on 0.3.251: the full option surface, no pid on SpawnedProcess (custom
  spawner stays mandatory), env defaulting to process.env when omitted, and
  --replay-user-messages appearing only via extraArgs.
- Exclude all eight bundled CLI platform binaries via
  ignoredOptionalDependencies. The setting lives in pnpm-workspace.yaml
  because pnpm 12 no longer reads the package.json "pnpm" field (it warns
  and ignores it; verified by install ablation). Excluding the binaries is
  what makes Orca's pathToClaudeCodeExecutable override mandatory rather
  than merely preferred. Note: pnpm 12.0.0 honors the ignore list when
  reconciling an existing lockfile but not on fresh resolution of a new
  dependency, so the lockfile's SDK entry was pinned surgically; both
  'pnpm install' and 'pnpm install --frozen-lockfile' verify clean and
  stable against the committed lockfile.
- Contract-pin suite drives the real SDK against a scripted fake CLI and pins:
  unknown type/field/content-block pass-through (and keep_alive interception),
  spawner env fidelity plus the omitted-env process.env inheritance sharp edge,
  extraArgs producing --replay-user-messages, argument parity for every
  CLAUDE_STRUCTURED_BASE_ARGS entry plus --session-id/--resume/
  --resume-session-at, canUseTool wire request_id stability and abort on
  control_cancel_request, one spawn per query, pathToClaudeCodeExecutable
  honored by the default spawner, the exact SDK version, and the eight platform
  binaries staying uninstalled.

Claude-Session: https://claude.ai/code/session_01FGCRfYUnb4hbvfTAHGtJKQ
2026-09-01 17:59:34 -07:00

65 lines
2.3 KiB
YAML

# The desktop app is a single-project install. `mobile/` is a separate workspace
# with its own pnpm-workspace.yaml and lockfile, so keep it out of the root
# package graph. Without this file `pnpm -r` auto-discovers mobile/ and its
# nested package, and the root's patchedDependencies fail as ERR_PNPM_UNUSED_PATCH.
packages: []
minimumReleaseAge: 4320
# 6.3.289 was published 2026-08-29T12:48Z; it clears the 3-day gate on 2026-09-01T12:48Z.
# zod 4.5.4 was published 2026-08-29T17:55Z; it clears the 3-day gate on 2026-09-01T17:55Z.
minimumReleaseAgeExclude:
- pdfjs-dist@6.3.289
- zod@4.5.4
shamefullyHoist: true
# Orca always launches the user's own resolved Claude CLI via
# pathToClaudeCodeExecutable, so the SDK's bundled ~95 MB-per-platform CLI
# binaries must never be installed. Excluding them is what makes the path
# override mandatory rather than merely preferred.
ignoredOptionalDependencies:
- '@anthropic-ai/claude-agent-sdk-darwin-arm64'
- '@anthropic-ai/claude-agent-sdk-darwin-x64'
- '@anthropic-ai/claude-agent-sdk-linux-arm64'
- '@anthropic-ai/claude-agent-sdk-linux-arm64-musl'
- '@anthropic-ai/claude-agent-sdk-linux-x64'
- '@anthropic-ai/claude-agent-sdk-linux-x64-musl'
- '@anthropic-ai/claude-agent-sdk-win32-arm64'
- '@anthropic-ai/claude-agent-sdk-win32-x64'
supportedArchitectures:
os:
- current
- darwin
- linux
- win32
cpu:
- current
- x64
- arm64
allowBuilds:
'@parcel/watcher': true
'@swc/core': false
'@vscode/windows-process-tree': false
agent-browser: false
cpu-features: true
electron-winstaller: false
esbuild: true
msw: false
node-pty: true
sherpa-onnx: true
ssh2: false
windows-native-registry: false
overrides:
monaco-editor>dompurify: 3.4.13
patchedDependencies:
node-pty@1.1.0: config/patches/node-pty@1.1.0.patch
'@xterm/addon-ligatures@0.11.0-beta.300': config/patches/@xterm__addon-ligatures@0.11.0-beta.300.patch
'@xterm/addon-webgl@0.20.0-beta.299': config/patches/@xterm__addon-webgl@0.20.0-beta.299.patch
'@xterm/addon-serialize@0.15.0-beta.300': config/patches/@xterm__addon-serialize@0.15.0-beta.300.patch
'@xterm/xterm@6.1.0-beta.303': config/patches/@xterm__xterm@6.1.0-beta.303.patch
lint-staged@16.4.0: config/patches/lint-staged@16.4.0.patch
'@vscode/windows-process-tree@0.8.0': config/patches/@vscode__windows-process-tree@0.8.0.patch