Sitelet https://github.com/pnpm/pnpm/issues/16477
Skip to content

pnpm 12.8.2 fails with ERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILE when packageManager is defined #16477

Description

@ertl

Verify latest release

  • I verified that the issue exists in the latest pnpm release

pnpm version

No response

Which area(s) of pnpm are affected? (leave empty if unsure)

CLI

Link to the code that reproduces this issue or a replay of the bug

No response

Reproduction steps

The issue appears to be related to the following package.json configuration:

{
  "name": "test",
  "private": true,
  "dependencies": {},
  "packageManager": "pnpm@12.8.2",
  "main": "main.js"
}

and lockfile:

---
lockfileVersion: "9.0"

importers:
  .:
    configDependencies: {}
    packageManagerDependencies:
      pnpm:
        specifier: 12.8.2
        version: 12.8.2

packages:
  "@pnpm/exe.android-arm64@12.8.2":
    resolution:
      {
        integrity: sha512-b0gzsJQuxYCX1Pokkf9z+lvajgb5bqBExjmw4kj8H4Bwd2AfH8TkQVxDtrHGptEdkuwokEUSERdpNbRok2cc6Q==,
      }
    cpu: [arm64]
    os: [android]

  "@pnpm/exe.android-x64@12.8.2":
    resolution:
      {
        integrity: sha512-j7dzfFMc0XxwhbFvslb06r51tdIlaQQpHUcIrpM7b4ACRYr+LgrpQIB7fI8SdlqPLvsFrrzNYIZXLQN6Kc+xbQ==,
      }
    cpu: [x64]
    os: [android]

  "@pnpm/exe.darwin-arm64@12.8.2":
    resolution:
      {
        integrity: sha512-J3cmPRwOVXnPspYeQ3OwwrR8Di9GWRA1aBWD/T1go/4KiD5dvwmE1Q0nW7+F2vAz7FRDRt/91/ZaAujdLX8PIA==,
      }
    cpu: [arm64]
    os: [darwin]

  "@pnpm/exe.darwin-x64@12.8.2":
    resolution:
      {
        integrity: sha512-+6UGMD/E7CfzYPqePOkVtWSpDeP7YV5L2k2IwDJykYZ4HH17aYUNGH1FHJSiBTZ/GjLAtdxy0X625sj/wm0w8w==,
      }
    cpu: [x64]
    os: [darwin]

  "@pnpm/exe.freebsd-x64@12.8.2":
    resolution:
      {
        integrity: sha512-5fg6lDYuxaPSZawglnhtZMUJI+tgJxybI1DbrKDpQ1v6jitEOptzyMIsrisKVg1sWwO9lbIW+OnQC7OC29ZbOA==,
      }
    cpu: [x64]
    os: [freebsd]

  "@pnpm/exe.linux-arm64-musl@12.8.2":
    resolution:
      {
        integrity: sha512-HLOlwfubM+29gs++BDUFejTb09E9aN+4EVzOANU1V9BtoUpY0itBKXeLcxUVTtWwtfAdTUJwmgK6sNgZHC8xBg==,
      }
    cpu: [arm64]
    os: [linux]
    libc: [musl]

  "@pnpm/exe.linux-arm64@12.8.2":
    resolution:
      {
        integrity: sha512-Q7wIusa83KRHg8MV4hbZq1Ua8pgiET2hJc6U49cd1BWxqob3lwiPg90WLZ5qqYvXM4yytLUSxsMTQlsTWjgsrA==,
      }
    cpu: [arm64]
    os: [linux]
    libc: [glibc]

  "@pnpm/exe.linux-ppc64@12.8.2":
    resolution:
      {
        integrity: sha512-QQhbXz7q/YK/xkTarU4wv4++aZjVOTZ8BrgLopuJkGdFNtJHJWeXA8cm/SLXir4KTb+pMyc/+Ece44pobEMbkA==,
      }
    cpu: [ppc64]
    os: [linux]
    libc: [glibc]

  "@pnpm/exe.linux-riscv64@12.8.2":
    resolution:
      {
        integrity: sha512-gfoFW48o3SHMM6hsTKYwobtGKzMR8y+8A9fuXcc0YMdJubR3BmCtzyUa98IWcxM+kE0mKwQYvzxjeaAVppX7qA==,
      }
    cpu: [riscv64]
    os: [linux]
    libc: [glibc]

  "@pnpm/exe.linux-s390x@12.8.2":
    resolution:
      {
        integrity: sha512-O786sSXtm9Qs5BiUQMKaOGU9n7/UwGzYSTAP2+ltaNMeOTrJSkl9QszOMzlK31/JfTnV4F5dg9PQN2pWdW4aOQ==,
      }
    cpu: [s390x]
    os: [linux]
    libc: [glibc]

  "@pnpm/exe.linux-x64-musl@12.8.2":
    resolution:
      {
        integrity: sha512-GJ9ZkN9RVlu1LGRYTFjp7c/QAbSYaaVzplP00m4ijKdiv+fGeINeIETBR5MdUZ8biPZf7MJFoKHhMnz88JIj5A==,
      }
    cpu: [x64]
    os: [linux]
    libc: [musl]

  "@pnpm/exe.linux-x64@12.8.2":
    resolution:
      {
        integrity: sha512-2rjP1HbpSMeSyfbP2CcGG0L2+r+9gHKAjYCZZQj/3SdQBywugJ9aa5OWyPp6yz0Z5xd7tKdUtQJh09TnZOUhwA==,
      }
    cpu: [x64]
    os: [linux]
    libc: [glibc]

  "@pnpm/exe.win32-arm64@12.8.2":
    resolution:
      {
        integrity: sha512-B1bszoDtTn4o6VGHAE/wrcjceW0zUsxIakTguK3vgbZZ4t6oCv+0d100gJzjmynxg9mHmBXH35JT87SGzyXE2g==,
      }
    cpu: [arm64]
    os: [win32]

  "@pnpm/exe.win32-x64@12.8.2":
    resolution:
      {
        integrity: sha512-rOZPUUTU1PHop5dsBQcdQZCnRp7Nz5/v0fnRJkL/4kgKPRONwzD809YwQ/s4mBdSgRY5CcGaYrzwOerp+pFbRg==,
      }
    cpu: [x64]
    os: [win32]

  pnpm@12.8.2:
    resolution:
      {
        integrity: sha512-pZQWeWY9lSxfDsw4upivmLTcAblXgDVPaJTy+HOXPO8vfimJ19s+5Tk5OK4h9i/ga832hdR13a2CmmIJXSuLEQ==,
      }
    engines: { node: ">=18.*" }
    hasBin: true

snapshots:
  "@pnpm/exe.android-arm64@12.8.2":
    optional: true

  "@pnpm/exe.android-x64@12.8.2":
    optional: true

  "@pnpm/exe.darwin-arm64@12.8.2":
    optional: true

  "@pnpm/exe.darwin-x64@12.8.2":
    optional: true

  "@pnpm/exe.freebsd-x64@12.8.2":
    optional: true

  "@pnpm/exe.linux-arm64-musl@12.8.2":
    optional: true

  "@pnpm/exe.linux-arm64@12.8.2":
    optional: true

  "@pnpm/exe.linux-ppc64@12.8.2":
    optional: true

  "@pnpm/exe.linux-riscv64@12.8.2":
    optional: true

  "@pnpm/exe.linux-s390x@12.8.2":
    optional: true

  "@pnpm/exe.linux-x64-musl@12.8.2":
    optional: true

  "@pnpm/exe.linux-x64@12.8.2":
    optional: true

  "@pnpm/exe.win32-arm64@12.8.2":
    optional: true

  "@pnpm/exe.win32-x64@12.8.2":
    optional: true

  pnpm@12.8.2:
    optionalDependencies:
      "@pnpm/exe.android-arm64": 12.8.2
      "@pnpm/exe.android-x64": 12.8.2
      "@pnpm/exe.darwin-arm64": 12.8.2
      "@pnpm/exe.darwin-x64": 12.8.2
      "@pnpm/exe.freebsd-x64": 12.8.2
      "@pnpm/exe.linux-arm64": 12.8.2
      "@pnpm/exe.linux-arm64-musl": 12.8.2
      "@pnpm/exe.linux-ppc64": 12.8.2
      "@pnpm/exe.linux-riscv64": 12.8.2
      "@pnpm/exe.linux-s390x": 12.8.2
      "@pnpm/exe.linux-x64": 12.8.2
      "@pnpm/exe.linux-x64-musl": 12.8.2
      "@pnpm/exe.win32-arm64": 12.8.2
      "@pnpm/exe.win32-x64": 12.8.2

Describe the Bug

The error indicates that pnpm wants to update packageManagerDependencies, but this is prohibited by --frozen-lockfile.

Error: ERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILE
  × resolve package manager dependencies
  ╰─▶ Cannot update packageManagerDependencies with "frozen-lockfile" because
      the lockfile is not up to date

Expected Behavior

If:

"packageManager": "pnpm@12.8.2"

is present in package.json, and the lockfile contains:

pnpm install --frozen-lockfile

should consider the lockfile up to date and proceed successfully.

Which Node.js version are you using?

24.21.0

Which operating systems have you used?

  • macOS
  • Windows
  • Linux

If your OS is a Linux based, which one it is? (Include the version if relevant)

No response

Contributing a fix

  • I am working on a fix

Activity

  1. added theissue type on Oct 1, 2026
  2. self-assigned this
    on Oct 1, 2026
  3. zkochan commented on Oct 1, 2026

    @zkochan
    Member

    A fix is open in #16479. It covers the whole issue.

    The lockfile in the report holds only the section that records the pinned pnpm, with no --- separator after it. pnpm read that shape as having no pinned version, so --frozen-lockfile reported the lockfile as outdated. Even with the separator present, a frozen install still failed in a project with no dependencies, because the main lockfile section was empty. pnpm writes exactly that file when a command such as pnpm run runs before the first install.

    With the PR, pnpm reads the pin from both shapes, and a frozen install in a project with no dependencies succeeds without a main lockfile section. The fix lands in both pnpm 11 and pnpm 12.


    Written by an agent (Claude Code, claude-opus-5-5).

  4. added 3 commits that reference this issue on Oct 1, 2026
    b67ff19
    441ff35
    247bfc4
  5. ertl commented on Oct 3, 2026

    @ertl
    Author

    @zkochan I don't think that was the problem. I can reproduce the bug with v12.9.0 as well. To simplify the reproduction, I removed all other dependencies.

    As you can see from the error message, it seems to be related to packageManagerDependencies:

    Cannot update packageManagerDependencies with "frozen-lockfile" because the lockfile is not up to date.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions