Addresses both Codex review findings:
- P1: add the missing `.changes/` entry. Typed `internal` per
`.changes/README.md`, which names dependency bumps with behaviour risk as
exactly that category.
- P2: the doc claimed pnpm leaves superseded package blocks in the lockfile.
It does not — it removes them. The old versions survive only as the
overrides' own selector keys in the `overrides:` block at the top of
`pnpm-lock.yaml`, which is what a naive grep actually hits. The practical
advice is unchanged (resolve on disk, do not grep), but the reason it gives
is now correct.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>