← All tasks
javascriptpnpm/pnpm #7934Not checked yet

`pnpm install --frozen-lockfile` fails with pnpm v9

envgap__pnpm__pnpm-7934

Original GitHub issue ↗Opened 2024-04-16

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not checked yet.
  • No curated issue-specific recipe or verified environment fix is available.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

pnpm/pnpm #7934 · read the original issue
### Verify latest release

- [X] I verified that the issue exists in the latest pnpm release

### pnpm version

9.0.0

### Which area(s) of pnpm are affected? (leave empty if unsure)

Lockfile

### Link to the code that reproduces this issue or a replay of the bug

https://github.com/DimensionDev/Maskbook/pull/11571/files

### Reproduction steps

Clone the PR and try an upgrade

### Describe the Bug

I upgraded pnpm from 8.7.6 to 9.0.0 and the lockfile is broken (as you can see in the link I mentioned).



One thing you can observe is that: peer dependencies to react are mostly resolved to 18.2.0, not `0.0.0-experimental-8039e6d0b-20231026` as I specified in `package.json/pnpm/peerDependencyRules/allowedVersions`.



I tried to remove the whole section of `allowedVersions` and reinstall, then add it back hope it can re-resolve dependencies, but that does not work.

### Expected Behavior

Upgrade and keep my peer dependencies version correct

### Which Node.js version are you using?

21

### Which operating systems have you used?

- [X] macOS
- [ ] Windows
- [ ] Linux

### If your OS is a Linux based, which one it is? (Include the version if relevant)

_No response_
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

Issue-specific recipe and runtime smoke command require review against the complete issue and repository.

Legacy reproduction is generic install-only; match the actual issue failure before admission.