refactor(cli)!: remove shadow bins for pnpm and yarn #889
+61
−566
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR removes shadow bin wrappers for pnpm and yarn, using direct spawning instead. Shadow bins are only needed for npm/npx security scanning. This change also converts all lazy
require()calls to static ES module imports throughout the refactored code paths.Changes
spawn()with WIN32 shell optioncreateRequire()and lazyrequire()with ES module importsBreaking Change
This is unlikely to affect users in practice since the functionality remains the same, but the internal mechanism has changed fundamentally.
Benefits
Test Plan
socket pnpmcommandssocket yarncommandsRelated
Part of broader effort to eliminate dynamic require() usage and simplify package manager command architecture.