Exact pins
| Field | Value |
|---|---|
| Tool | Node |
| Enable via | house-rules-pins bin |
| Bin | house-rules-pins |
| Source | packages/rules/bin/pins.mjs |
| Docs | packages/rules/docs/pins.md |
What it catches
Section titled “What it catches”Every dependency must be an exact version, workspace:<exact>, or a Git spec with full commit SHA.
Rule docs
Section titled “Rule docs”From packages/rules/docs/pins.md.
Bin: house-rules-pins (bin/pins.mjs)
Moved from drunk-cat-stack’s scripts/check-exact-pins.mjs with the same behavior, messages and exit codes. Its tests moved too, to tests/pins.test.mjs. Since then it also accepts a commit-pinned Git spec with a pnpm &path: subpath.
{ "scripts": { "pins": "house-rules-pins" }}What passes
Section titled “What passes”Every entry in dependencies, devDependencies and optionalDependencies must be one of:
- an exact version, prerelease or build included:
1.2.3,4.0.0-rc.1 - an npm alias to an exact version:
npm:[email protected] workspace:plus an exact version:workspace:0.0.0- a Git spec pinned to a full 40-character commit:
github:owner/repo#<sha>,git+https://...#<sha>,git+ssh://...#<sha> - the same Git spec plus a pnpm subpath after the commit:
github:owner/repo#<sha>&path:/packages/rules. The path starts with/, has no empty,.or..segment, and no trailing/. A branch, tag or short SHA before&path:still fails.
packageManager, when set, must end in an exact version.
Which manifests
Section titled “Which manifests”- With arguments, it checks exactly those
package.jsonpaths. - Without arguments, it reads the
packages:list frompnpm-workspace.yamlin the working directory, and checks the rootpackage.jsonplus every matching<pattern>/package.json. Nopackages:list is an error.
Output and exit codes
Section titled “Output and exit codes”0: printspins: every dependency is exact in <paths>.1: printsDependencies in <path> must be exact versions or full commit SHAs:and one<field>.<name>: <spec>line per loose entry, to stderr.