* Migrate from Yarn to pnpm
Switch the package manager to pnpm 11, keeping every resolved
dependency version from yarn.lock.
- Move resolutions to pnpm overrides and Yarn patches to patches/
- Enable supply-chain protection: 3 day minimum release age,
trust policy that blocks provenance downgrades, and dependency
build scripts denied by default
- Declare dependencies that were imported but only available through
Yarn's hoisting: zrender, @lezer/common, zxing-wasm,
@babel/helper-compilation-targets, core-js-compat, @types/geojson
- Look up pinned license overrides in pnpm's node_modules layout
- Update CI, scripts, git hooks, Renovate, and documentation
* Cache the pnpm store with node_modules in CI
Jobs that restore the shared node_modules cache skip the install, so
the pnpm store is empty there. The license file generation runs
`pnpm licenses list`, which reads package metadata from the store and
fails without it.
* Point the demo e2e comment at the real test:e2e:demo script
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Shared build and runner for all build,dev,test flows
* Harden managed process lifecycle
* Make build workflows deterministic
* Test build management contracts
* Queue shared generated output work
* Isolate generated inputs for dev servers
* Preserve dev server child failures
* Make generated lock test deterministic
* Keep test navigator configurable
* Block concurrent frontend workflows
* Simplify workflow lock ownership
* Focus workflow locking on managed commands
* Trim workflow lock unit tests
* Consolidate dev server lifecycle handlers
* Generate third party license file during production build
* Add license check CI step
* Address review comments: use license-checker-rseidelsohn, add version validation for LICENSE_OVERRIDES
* Fix license-checker-rseidelsohn import (CJS module, use require)
* Made it easier to test the frontend against an existing core instance.
* Ensured that script works regardless of current working dir
* Use consistent quote style
* Also allow using variables in hassUrl override
* Improved the default behavior of the script
* more consistent variable naming
* don't install a global dependency
* documented caching wierdness where if you switch core endpoints the old one remains in use
* Simplified some code
* improved documentation
---------
Co-authored-by: Petar Petrov <MindFreeze@users.noreply.github.com>