Files
pmg/sandbox/profiles/pnpm-restrictive.yml
T
Abhisek DattaandGitHub b56a8e2a43 chore: Show cloud credentials store in setup info (#236)
* chore: Show cloud credentials store in setup info

* fix: pnpm sandbox policy for atomic write
2026-05-04 16:24:49 +00:00

30 lines
836 B
YAML

name: pnpm-restrictive
description: Profile for pnpm with write access to current directory
inherits: npm-restrictive
package_managers:
- pnpm
filesystem:
allow_write:
# pnpm needs write access here
- ${HOME}/Library/pnpm/.tools/**
- ${HOME}/.pnpm-store/**
# `pnpm i` creates the tmp files in local dir, at least on MacOS
- ${CWD}/_tmp_*
# pnpm self-update (or likely update) creates temporary package.json files
# for writing. This is likely for atomic update using filesystem rename operation
# which guarantees atomicity
- ${CWD}/package.json.*
# pnpm install/update writes pnpm-lock.yaml atomically via a sibling
# temp file (e.g. pnpm-lock.yaml.139703784) followed by rename.
- ${CWD}/pnpm-lock.yaml.*
# Need access for dependency resolution
- ${CWD}/.pnpm-store