pnpm 11.28.3 updates undici to clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named like constructor work.
Patch Changes
Installing packages
-
pnpm now ships
undici7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v. -
pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.
-
Names that match built-in JavaScript object properties, such as
constructor,toString, or__proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:pnpm add,pnpm install, andpnpm import, for dependencies, peer dependencies, andfile:dependencies that point to a directory namedconstructor.- Catalog entries and catalog names. Pruning unused entries crashed, and a new catalog named
toStringwas not written. - Workspace projects, project directories, and files inside injected packages.
- Registry prefixes and override version references such as
$toString. - Hoisting,
pnpm list, andpnpm why. - Command names.
pnpm constructorruns theconstructorscript like any other unknown command, andpnpm help constructorno longer crashes. - Resolving through a pnpr server when a project lives in a directory named
constructor.
-
pnpm installno longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #16418. -
POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377. -
In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before,
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353. -
pnpm now fails with
ERR_PNPM_INVALID_ALLOW_BUILDSwhenallowBuildsis not an object or one of its values is nottrue,false, or a string. Such values used to be ignored silently. -
Removing a dependency whose bins are declared through
directories.binno longer leaves broken shims innode_modules/.bin. -
A custom resolver's
shouldRefreshResolutionhook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.
Updating dependencies
-
When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new1.0.0is too new, pnpm picks1.0.0-beta.4rather than an old0.0.1#16388. -
pnpm --filter <project> update <pkg>now fails withERR_PNPM_NO_PACKAGE_IN_DEPENDENCIESwhen the selected projects do not depend on<pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully. -
pnpm audit --fixnow updates vulnerable packages in a single project that setsupdateConfig.ignoreDependencies. It used to leave them on the vulnerable version. -
pnpm update --globalnow removes hard-linked executables fromPNPM_HOMEwhen migrating packages from the old global layout #16420. -
Updating a pinned GitHub Action now rewrites the version in its
# vX.Y.Zcomment even when the action name contains the same version text. The action name used to change while the comment kept the old version.
Workspaces and deploy
-
pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package also lists its peer dependency as a dev dependency #16375. -
pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403. -
--filterfixes:- A
...pkg...selector combined with another dependents selector, such as--filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents. --filter "[<since>]"now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.
- A
Running scripts
-
After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.
-
A lifecycle script run with
unsafePerm: falsenow fails with an error when pnpm cannot createnode_modules/.tmp. It used to hang. -
pnpm runwithverifyDepsBeforeRunno longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load. -
pnpm run -rnow closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it. -
pnpm run --resume-fromno longer crashes when a saved run state file containsnull.
Store
-
pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used, as long as the store still has another registered project. They used to stay until the nextpnpm store prune#16383. -
pnpm store prunenow stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.
Publishing and registry output
-
pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704. -
pnpm pack-appnow accepts an entry file or output directory inside the project whose name starts with two dots, such as..build/entry.cjs. It used to fail withERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT. -
Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.
Platinum Sponsors
|
|
|
|
|
|
Gold Sponsors
|
|
|
|
|
|
|
|
|
|
|