None of this was caught because nothing ever ran on Windows: every job in every
workflow was ubuntu-latest, and checks.yml did not even run on the PR that
reported it — only Vercel, which failed on fork authorization.
The check job now runs on both, fail-fast off so a Windows-only break still
reports the Linux result. `shell: bash` on the multi-line steps, since the
default shell there is pwsh, which shares none of that syntax; Git Bash ships
on the runner, so nothing needs rewriting. The two drift checks stay Linux-only
— they verify that a committed generated file matches its generator, which is a
property of the repo, not of the platform.
The new build step is unconditional and unscoped on purpose. `--affected` is
exactly what let these through: they lived in build scripts, so a PR touching
no affected package never ran them. A `pnpm clean` step guards the lane that
was broken in all eleven packages.
pnpm-workspace.yaml's release-age exclusions had drifted almost across the
board — turbo pinned at 2.10.1 against 2.10.9 in the lockfile, the Claude SDK
at 0.3.196 against 0.3.226, both codex packages a minor behind. A stale pin
does not fail loudly; it simply stops excluding anything, and the package falls
back under the gate. That is the silent optional-dep drop the file's own
esbuild comment documents, and every one of these ships per-platform packages
including win32.