packages:
  - "mcps/*"
  - "web"

# pnpm 11 default `strictDepBuilds: true` blocks install scripts for any
# dependency with a build script (esbuild's native binary fetch, sharp,
# etc.) unless individually allowlisted, and fails the whole `install`
# with ERR_PNPM_IGNORED_BUILDS otherwise. Scaffolded apps pull in build-
# script deps transitively (tsup/vite -> esbuild, mcp/ui deps, etc.) that
# we can't enumerate up front, so match pnpm 9/10 behavior here.
strictDepBuilds: false

# pnpm 11 default `verifyDepsBeforeRun: 'install'` re-verifies the
# lockfile against supply-chain policies (including minimumReleaseAge)
# before every `pnpm run <script>`, hitting the registry even for
# already-installed deps. That check 404s for any dependency that only
# exists as a local tarball (not yet published), which is expected
# during local/dev/CI installs. Restore pnpm 9/10 behavior: only verify
# on an explicit `pnpm install`.
verifyDepsBeforeRun: false

# See above — same registry-lookback problem hits a plain `pnpm install`
# too when minimumReleaseAge is nonzero; disable it for scaffolded apps.
minimumReleaseAge: 0

# pnpm ≥10 reads the build-script allow/deny lists HERE — package.json's
# `pnpm.onlyBuiltDependencies` is ignored and WARNs on every first install
# (guuey#978, the founder's first prod scaffold). esbuild's postinstall is
# allowed (the binary fetch). The transitive build-script deps a scaffold
# pulls — none run by the worker's own code — are ignored EXPLICITLY, which
# is exactly what pnpm did silently before while printing the
# "Ignored build scripts … run pnpm approve-builds" box; naming them keeps
# a customer's first minute quiet without changing what gets built.
onlyBuiltDependencies:
  - esbuild
ignoredBuiltDependencies:
  - "@google/genai"
  - onnxruntime-node
  - protobufjs
  - sharp
