Minor Changes
-
Added a new setting,
update.githubActionsServer, for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files (for example, a GitHub Enterprise Server). When the setting is not defined, the URL is read from theGITHUB_SERVER_URLenvironment variable, falling back tohttps://github.com. The URL must use thehttps://orhttp://protocol #13220.pnpm outdatedandpnpm updateno longer fail when the refs of a GitHub Action's repository cannot be read (for example, when the action's repository is private or hosted on a different GitHub server). Such actions are now skipped with a warning.Setting
update.githubActionstofalsenow makespnpm outdatedand the interactivepnpm updateskip GitHub Actions dependencies. -
Added the
pnpm unpublishcommand: remove a package from the registry entirely (requires--force), or remove the versions matching<package>@<range>, re-pointingdist-tagsthat referenced them and deleting the orphaned tarballs. Supports--registryand--otp.
Patch Changes
-
The token poll for web-based authentication no longer reads the body of non-OK or still-pending (HTTP 202) responses, and caps the token response body it does read at 64 KiB, so a malicious or compromised registry cannot exhaust memory through the poll pnpm/pnpm#12721.
-
pnpm install --no-runtimenow works without--frozen-lockfile: on a fresh install, runtime dependencies are resolved and recorded in the lockfile, but their archives are not downloaded and their bins are not linked. -
pnpm outdatednow aligns its table borders when the output is colorized. The color escape codes in thePackageandLatestcells were being counted as visible characters, so the columns and box-drawing borders drifted out of alignment on a terminal. -
pnpm packandpnpm publishno longer let workspace-root.gitignore/.npmignorerules exclude files matched by the package manifest'sfilesallowlist. Workspace packages whose build output is gitignored at the workspace root (for example a compiledlib/directory listed infiles) were published with almost all payload files missing #13164. -
Fixed
pnpm update --latestfailing withERR_PNPM_PACKAGE_MANAGER_UPDATE_RESOLVE_LATESTwhen a dependency uses theworkspace:(orlink:/file:) protocol. Such a dependency links a local package that may not be published, so there is no registry "latest" to resolve — it is now skipped and preserved verbatim, matching the TypeScript CLI. Previously onlyworkspace:<path>specifiers were skipped, soworkspace:*/workspace:^1.0.0deps pointing at unpublished packages made--latesttry to fetch them from the registry and 404. -
pnpm viewnow accepts the--registryoption, matching the TypeScript CLI. Previously the flag was rejected as an unknown argument. -
When the authentication URL cannot be rendered as a QR code (for example when it exceeds the maximum QR data capacity), web-based login now displays the URL alone with a warning instead of aborting authentication pnpm/pnpm#12721.