Skip to content

Exact pins

Field Value
Tool Node
Enable via house-rules-pins bin
Bin house-rules-pins
Source packages/rules/bin/pins.mjs
Docs packages/rules/docs/pins.md

Every dependency must be an exact version, workspace:<exact>, or a Git spec with full commit SHA.

From packages/rules/docs/pins.md.

Bin: house-rules-pins (bin/pins.mjs)

Moved from drunk-cat-stack’s scripts/check-exact-pins.mjs with the same behavior, messages and exit codes. Its tests moved too, to tests/pins.test.mjs. Since then it also accepts a commit-pinned Git spec with a pnpm &path: subpath.

package.json
{
"scripts": {
"pins": "house-rules-pins"
}
}

Every entry in dependencies, devDependencies and optionalDependencies must be one of:

  • an exact version, prerelease or build included: 1.2.3, 4.0.0-rc.1
  • an npm alias to an exact version: npm:[email protected]
  • workspace: plus an exact version: workspace:0.0.0
  • a Git spec pinned to a full 40-character commit: github:owner/repo#<sha>, git+https://...#<sha>, git+ssh://...#<sha>
  • the same Git spec plus a pnpm subpath after the commit: github:owner/repo#<sha>&path:/packages/rules. The path starts with /, has no empty, . or .. segment, and no trailing /. A branch, tag or short SHA before &path: still fails.

packageManager, when set, must end in an exact version.

  • With arguments, it checks exactly those package.json paths.
  • Without arguments, it reads the packages: list from pnpm-workspace.yaml in the working directory, and checks the root package.json plus every matching <pattern>/package.json. No packages: list is an error.
  • 0: prints pins: every dependency is exact in <paths>.
  • 1: prints Dependencies in <path> must be exact versions or full commit SHAs: and one <field>.<name>: <spec> line per loose entry, to stderr.

All rules · Node rules