Skip to content

feat: support package.json5 in package_json_file - #290

Open
skagedal wants to merge 8 commits into
pnpm:masterfrom
skagedal:json5-package-manifest
Open

skagedal wants to merge 8 commits into
pnpm:masterfrom
skagedal:json5-package-manifest

Conversation

@skagedal

@skagedal skagedal commented Sep 25, 2026 •

Copy link
Copy Markdown

Reads packageManager and devEngines.packageManager from a package.json5 manifest, so package_json_file: package.json5 works the same way as package.json and package.yaml.

The action does not pick a manifest by itself. The package_json_file input already names the file to read, and it accepted package.json and package.yaml. This PR adds package.json5 to that list, and the file extension decides the parser. A project that keeps both a stub package.json and a real package.json5 sets package_json_file: package.json5. This is separate from pnpm/pnpm#11372, which adds a preferredManifestFormat setting that tells pnpm itself which of several coexisting manifests to use. The action needs no equivalent, because the input already says which file to read.

This continues #191 by kokoichi206, which was approved but has gone stale against master. Their commits are kept as they are. On top of them:

  • Merged master and resolved the conflicts: the semver dependency, the pnpm v12 changes in run.ts, and the README wording for devEngines.packageManager.
  • Picked the parser with a switch on the file extension, as suggested in review. .yaml uses YAML, .json5 uses JSON5, and everything else uses plain JSON.
  • Updated the package_json_file description in action.yml to mention package.yaml and package.json5.
  • Added a test.yaml matrix case that writes a package.json5 using JSON5-only syntax (a comment, an unquoted key, a trailing comma) and checks that the pinned version gets installed.
  • Rebuilt dist/index.js.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added support for reading package manager settings from package.json5 manifests, alongside package.json and package.yaml.
    • The action can read settings from either packageManager or devEngines.packageManager in supported manifests, making it compatible with projects that use either configuration format.

kokoichi206 and others added 7 commits November 15, 2025 08:15
Co-authored-by: Khải <hvksmr1996@gmail.com>
…e.json5

Address review comments on pnpm#191: use a switch on the
file extension, mention package.yaml and package.json5 in action.yml,
and add a CI case that reads packageManager from a package.json5.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: d0e1d0fb-9a79-4773-ae06-d947c97bfd25

📥 Commits

Reviewing files that changed from the base of the PR and between 18f18a5 and e1d4181.

📒 Files selected for processing (1)
  • README.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • README.md

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: Greptile Review

📝 Walkthrough

Walkthrough

The action now parses JSON5 manifests alongside JSON and YAML. The manifest-pin workflow writes to the configured filename, passes that filename to the action, and includes a package.json5 test case.

Changes

JSON5 manifest support

Layer / File(s) Summary
Manifest format parsing
action.yml, README.md, package.json, src/install-pnpm/run.ts
The input descriptions list package.json5. The action uses extension-based parsing for YAML, JSON5, and standard JSON when it reads the target version.
Configured manifest test coverage
.github/workflows/test.yaml
The workflow writes each manifest to its configured filename, passes that filename to the action, and adds a package.json5 case.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to e1d41

JSON5 manifest support appears ready to merge after normal checks.

Architecture Summary

Architecture risk: 🟡 Medium · up to 18f18

The change affects 4 systems.

Changed systems: src, action.yml, package.json, README.md

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — src (service) was modified; 1 changed file maps to changed impact.
  • observed — action.yml (service) was modified; 1 changed file maps to changed impact.
  • observed — package.json (service) was modified; 1 changed file maps to changed impact.
  • observed — README.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in README.md: The package_json_file description adds package.json5 to the listed formats used to read package-manager configuration.
  • observed — Modified behavior in action.yml: The package_json_file description now includes package.yaml and package.json5 and names devEngines.packageManager alongside packageManager as configuration to read.
  • observed — Modified behavior in package.json: Added json5 (^2.2.3) as a runtime dependency.
  • observed — Modified behavior in src/install-pnpm/run.ts: Adds the JSON5 parser import.

Reliability and maintainability

  • inferred — Risk-relevant change factors for src: blast_radius_1; direct_dependents_1
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding support for package.json5 in package_json_file.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads JSON5 by moonlit glow,
Then checks YAML and JSON in a row.
The workflow writes the chosen name,
And tests the format in its game.
I twitch my nose: the manifests flow!

Comment @coderabbitai help to get the list of available commands.

skagedal added a commit to skagedal/iggybilly that referenced this pull request Sep 26, 2026
Use a fork of pnpm/action-setup that reads package.json5, so CI runs the
pnpm that packageManager pins instead of the latest 10.x. Switch back to
pnpm/action-setup once pnpm/action-setup#290 lands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@skagedal
skagedal marked this pull request as ready for review September 26, 2026 10:04
@skagedal
skagedal requested a review from zkochan as a code owner September 26, 2026 10:04
@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Adds support for reading package.json5 manifest files.

The PR appears safe to merge based on the changes since the previous review.

Reviews (2) · Last reviewed commit: "Update README.md"

Comment thread README.md Outdated
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants