pnpm Blog

フィード

記事のアイキャッチ画像
Why pnpm no longer expands environment variables in a repository's .npmrc
pnpm Blog
pnpm used to expand $ placeholders everywhere it found them — including in the .npmrc and pnpm-workspace.yaml files that live inside the repository you just cloned. That turned out to be a way for a malicious repository to steal the secrets in your environment. As of v10.34.2 and v11.5.3, pnpm stops expanding environment variables in repository-controlled registry and credential settings.
4日前
記事のアイキャッチ画像
pnpm 11.5
pnpm Blog
pnpm 11.5 adds a hoistingLimits setting for controlling how far dependencies hoist in nodeLinker: hoisted installs, replaces the interactive prompt library to fix scrolling in long choice lists, recognizes staged publishes in the trust scale, and ships several install and dist-tag fixes.
17日前
記事のアイキャッチ画像
pnpm 11.4
pnpm Blog
pnpm 11.4 closes a cluster of supply-chain holes around lockfile integrity, credential scoping, git resolutions, patch files, and dependency aliases, makes tarball-integrity mismatches a hard install failure by default (with a narrowly-scoped --update-checksums opt-in), and changes pnpm runtime set to write to devEngines.runtime instead of engines.runtime by default.
19日前
記事のアイキャッチ画像
pnpm 11.3
pnpm Blog
pnpm 11.3 adds support for npm's staged publishing (pnpm stage), the new trustLockfile setting for skipping the supply-chain verification pass on already-trusted lockfiles, and native implementations of pnpm pkg, pnpm repo, and pnpm set-script. It also adds a --skip-manifest-obfuscation flag for pack / publish and cuts the memory footprint of minimumReleaseAge / trustPolicy verification on large workspaces.
22日前
記事のアイキャッチ画像
pnpm 11.2
pnpm Blog
pnpm 11.2 ships an experimental opt-in into pacquet (the Rust port of pnpm) as the install backend, expands config dependencies to install one level of optionalDependencies (so the esbuild/swc platform-binary pattern works for config deps too), wires up the long-documented pnpm login --scope flag, and surfaces runtime entries (Node.js, Deno, Bun) in pnpm outdated and pnpm update --interactive.
1ヶ月前
記事のアイキャッチ画像
pnpm 11.1
pnpm Blog
pnpm 11.1 adds a few new commands — pnpm audit signatures, pnpm bugs, and pnpm owner — alongside support for installing from arbitrary named registries (including a built-in alias for the GitHub Packages npm registry), the ability to skip runtime installation in CI, and several fixes.
1ヶ月前
記事のアイキャッチ画像
pnpm 11.0
pnpm Blog
pnpm 11 is here! This release tightens the security defaults introduced throughout the v10 cycle, drops the npm CLI fallback for publishing in favor of a native implementation, replaces the JSON-per-package store index with a single SQLite database, and isolates global installs so they no longer interfere with each other.
2ヶ月前
記事のアイキャッチ画像
pnpm 10.32
pnpm Blog
pnpm 10.32 adds an --all flag to pnpm approve-builds for approving all pending builds without interactive prompts.
3ヶ月前
記事のアイキャッチ画像
pnpm 10.31
pnpm Blog
pnpm 10.31 preserves comments and formatting when updating pnpm-workspace.yaml, and includes numerous bug fixes.
3ヶ月前
記事のアイキャッチ画像
pnpm 10.30
pnpm Blog
pnpm 10.30 redesigns pnpm why to show a reverse dependency tree, making it much easier to understand why a package is installed.
4ヶ月前
記事のアイキャッチ画像
pnpm 10.29
pnpm Blog
pnpm 10.29 adds catalog specifier, and includes several bug fixes.
4ヶ月前
記事のアイキャッチ画像
pnpm 10.28
pnpm Blog
pnpm 10.28 introduces a new beforePacking hook to customize package.json at publish time, improves filtered install performance, and includes several bug fixes.
5ヶ月前
記事のアイキャッチ画像
pnpm 10.27
pnpm Blog
pnpm 10.27 adds a new setting to ignore trust policy checks for older package versions, introduces a project registry for global virtual store pruning, and includes several bug fixes.
6ヶ月前
記事のアイキャッチ画像
🚀 pnpm in 2025
pnpm Blog
2025 has been a transformative year for pnpm. While our primary focus was redefining the security model of package management, we also delivered significant improvements in performance and developer experience.
6ヶ月前
記事のアイキャッチ画像
pnpm 10.26
pnpm Blog
pnpm 10.26 introduces stricter security defaults for git-hosted dependencies, adds allowBuilds for granular script permissions, and includes a new setting to block exotic transitive dependencies.
6ヶ月前
記事のアイキャッチ画像
pnpm 10.25
pnpm Blog
pnpm 10.25 improves certificate handling, adds a bare pnpm init, and ships several quality-of-life fixes.
6ヶ月前
記事のアイキャッチ画像
How We're Protecting Our Newsroom from npm Supply Chain Attacks
pnpm Blog
We got lucky with Shai-Hulud 2.0.
6ヶ月前
記事のアイキャッチ画像
pnpm 10.24
pnpm Blog
pnpm now scales network concurrency automatically on high-core machines and ships several reliability fixes.
7ヶ月前
記事のアイキャッチ画像
pnpm 10.23
pnpm Blog
Added --lockfile-only option to pnpm list and various improvements to pnpm self-update.
7ヶ月前
記事のアイキャッチ画像
pnpm 10.22
pnpm Blog
Added support for excluding packages from trust policy and overriding the engines field on publish.
7ヶ月前