Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/actions/pnpmInstallWithRetries/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
name: pnpm-install-with-retries
description: 'wraps `pnpm install --frozen-lockfile` with retries/timeout to handle network failures'
inputs:
ignore-scripts:
default: 'false'
description: 'Skip pre/post install scripts'
runs:
using: composite
steps:
- name: pnpm install
uses: salesforcecli/github-workflows/.github/actions/retry@main
with:
command: pnpm install --frozen-lockfile ${{ inputs.ignore-scripts == 'true' && '--ignore-scripts' || '' }}
8 changes: 6 additions & 2 deletions .github/actions/setupNodeAndInstall/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,8 +69,12 @@ runs:
if: inputs.package-manager == 'yarn' && steps.install-command.outputs.value == 'yarn install --network-timeout 600000'
uses: salesforcecli/github-workflows/.github/actions/yarnInstallWithRetries@main

- name: Install custom or pnpm dependencies
if: (inputs.package-manager != 'npm' || steps.install-command.outputs.value != 'npm ci') && (inputs.package-manager != 'yarn' || steps.install-command.outputs.value != 'yarn install --network-timeout 600000')
- name: Install pnpm dependencies
if: inputs.package-manager == 'pnpm' && steps.install-command.outputs.value == 'pnpm install --frozen-lockfile'
uses: salesforcecli/github-workflows/.github/actions/pnpmInstallWithRetries@main

- name: Install custom dependencies
if: (inputs.package-manager != 'npm' || steps.install-command.outputs.value != 'npm ci') && (inputs.package-manager != 'yarn' || steps.install-command.outputs.value != 'yarn install --network-timeout 600000') && (inputs.package-manager != 'pnpm' || steps.install-command.outputs.value != 'pnpm install --frozen-lockfile')
uses: salesforcecli/github-workflows/.github/actions/retry@main
with:
command: ${{ steps.install-command.outputs.value }}
4 changes: 1 addition & 3 deletions .github/workflows/npmPublish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -167,9 +167,7 @@ jobs:
uses: salesforcecli/github-workflows/.github/actions/npmInstallWithRetries@main
- name: Install dependencies with pnpm
if: inputs.packageManager == 'pnpm'
uses: salesforcecli/github-workflows/.github/actions/retry@main
with:
command: pnpm install --frozen-lockfile
uses: salesforcecli/github-workflows/.github/actions/pnpmInstallWithRetries@main
- name: Vulnerability check
if: inputs.vulnerabilityCheck
# Check for known vulnerable packages from the following supply chain attacks:
Expand Down
51 changes: 51 additions & 0 deletions plans/W-24093892.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# W-24093892 — 2.2 Add pnpmInstallWithRetries sibling action

## Context

`setupNodeAndInstall` already installs npm and Yarn through sibling composite actions, and resolves the default pnpm install to `pnpm install --frozen-lockfile`. That pnpm command still runs through the generic `retry` step (`.github/actions/setupNodeAndInstall/action.yml`).

Add `.github/actions/pnpmInstallWithRetries/action.yml` next to:

- `.github/actions/npmInstallWithRetries/action.yml` — `npm ci` via `retry`, `ignore-scripts` input
- `.github/actions/yarnInstallWithRetries/action.yml` — `yarn install --network-timeout 600000` via `retry`, `ignore-scripts` input

Route the default pnpm command in `setupNodeAndInstall` through the new action. Custom `install-command` values stay on the generic `retry` step.
Comment thread
mshanemc marked this conversation as resolved.

## Phases

### 1. Add the pnpm sibling and call it from setupNodeAndInstall

Commit: `Add pnpmInstallWithRetries for the default frozen-lockfile install`

Files:

- `.github/actions/pnpmInstallWithRetries/action.yml` (new)
- `.github/actions/setupNodeAndInstall/action.yml`

`pnpmInstallWithRetries` is a composite action:

- `name`: `pnpm-install-with-retries`
- `description`: wraps `pnpm install --frozen-lockfile` with retries/timeout to handle network failures
- input `ignore-scripts`, default `'false'`, same description as the npm and yarn actions
- one step, `pnpm install`, `uses: salesforcecli/github-workflows/.github/actions/retry@main`
- `command`: `pnpm install --frozen-lockfile ${{ inputs.ignore-scripts == 'true' && '--ignore-scripts' || '' }}`

In `setupNodeAndInstall`, after the Yarn install step, add:

- name `Install pnpm dependencies`
- `if: inputs.package-manager == 'pnpm' && steps.install-command.outputs.value == 'pnpm install --frozen-lockfile'`
- `uses: salesforcecli/github-workflows/.github/actions/pnpmInstallWithRetries@main`

Extend the existing custom-install `if` with `(inputs.package-manager != 'pnpm' || steps.install-command.outputs.value != 'pnpm install --frozen-lockfile')` so the default pnpm command is only installed by the sibling. Rename that step from `Install custom or pnpm dependencies` to `Install custom dependencies`.

`setupNodeAndInstall` does not pass `ignore-scripts` into the npm or yarn actions; the pnpm call matches that.

## Skills to apply

Follow the composite-action shape already in `npmInstallWithRetries` and `yarnInstallWithRetries`: shared `retry` action, `ignore-scripts` input, install command equal to the string `setupNodeAndInstall` already resolves for that package manager (`pnpm install --frozen-lockfile` at the `Resolve install command` step).

## Verification

- New action inputs and `retry` usage match the npm and yarn siblings, with the install command `pnpm install --frozen-lockfile`.
- `setupNodeAndInstall` default paths are exclusive: `npm` + `npm ci` → `npmInstallWithRetries`; `yarn` + `yarn install --network-timeout 600000` → `yarnInstallWithRetries`; `pnpm` + `pnpm install --frozen-lockfile` → `pnpmInstallWithRetries`; every other resolved command → `retry`.
- Direct `npmInstallWithRetries` and `yarnInstallWithRetries` workflow uses stay unchanged.