← All tasks
javascriptpnpm/pnpm #5106Not checked yet

Non-deterministic install

envgap__pnpm__pnpm-5106

Original GitHub issue ↗Opened 2022-07-27

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not checked yet.
  • No curated issue-specific recipe or verified environment fix is available.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

pnpm/pnpm #5106 · read the original issue
I discovered a case where `pnpm install` doesn't behave deterministically — when being run again and again, a package (`promise-inflight`) is sometimes added and sometimes removed, resulting in changes in `pnpm-lock.yaml`.



I'm linking [a repository](https://github.com/JanJakes/pnpm-nondeterministic-install) with the issue reproduction. Note that there are many missing peer deps as I was trying to cut down the dependencies and still reproduce the issue.



### pnpm version:

7.6.0



### Code to reproduce the issue:

https://github.com/JanJakes/pnpm-nondeterministic-install



### Expected behavior:

No matter how many times I run `pnpm install` consecutively, there should be no changes in `pnpm-lock.yaml` and `node_modules`.



### Actual behavior:

When `pnpm install` is being run repeatedly, a package keeps being randomly added and removed.



### Additional information:

All details are in the readme of the issue reproduction: https://github.com/JanJakes/pnpm-nondeterministic-install
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

security
Label rules and the text that matched
[
  {
    "category": "security",
    "rule": "issue.security_keyword",
    "source": "issue_body",
    "excerpt": "gain, a package (`promise-inflight`) is sometimes added and sometimes removed, resulting in changes in `pnpm-lock.yaml`.\r\n\r\nI'm linking [a repository](https://github.com/JanJake"
  }
]

Issue-specific recipe and runtime smoke command require review against the complete issue and repository.

Legacy reproduction is generic install-only; match the actual issue failure before admission.