Skip to content

bug: chokidar@4 triggering ERR_PNPM_TRUST_DOWNGRADE during onboarding #3787

@joeyfigaro

Description

@joeyfigaro

Provide environment information

System:
    OS: macOS x.x.x
    CPU: (14) arm64 Apple M4 Pro
    Memory: xx / 48.00 GB
    Shell: x.x - /bin/zsh

Binaries:
    Node: 24.0.2 - /Users/xxx/.local/state/fnm_multishells/yyy/bin/node
    Yarn: 1.22.22 - /Users/xxx/.local/state/fnm_multishells/yyy/bin/yarn
    npm: 11.3.0 - /Users/xxx/.local/state/fnm_multishells/yyy/bin/npm
    pnpm: 10.27.0 - /Users/xxx/.local/state/fnm_multishells/yyy/bin/pnpm

Describe the bug

 ERR_PNPM_TRUST_DOWNGRADE  High-risk trust downgrade for "chokidar@4.0.3" (possible package takeover)

This error happened while installing the dependencies of trigger.dev@4.4.6
 at @trigger.dev/build@4.4.6
 at @prisma/config@6.19.3
 at c12@3.1.0

Just a heads up! This was encountered in the first step of your onboarding, which is likely turning folks away.

Reproduction repo

N/A

To reproduce

  1. Sign into trigger.dev for the first time
  2. Follow first onboarding step for taskspnpm dlx trigger.dev@latest init -p xxx

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions