This release adds an experimental loaded node linker, lets pnpm-lock.yaml record resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.
Minor Changes
-
Added experimental
nodeLinker: { type: loaded }installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader.nodeLinker.excludedselects packages and their dependency trees to install in the global virtual store. -
lockfile.includeResolutionSettings: truemakespnpm-lock.yamlrecordautoDedupe,dedupeInjectedDeps,dedupePeerDependentsandlinkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that recordsautoDedupeis reused by later installs on any machine, sopnpm runafterpnpm install --frozen-lockfileno longer starts another install #16583.
Patch Changes
Security
-
pnpm installnow prevents dependency versions with path traversal from writing files outside the global virtual store. -
pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with
version+integrity. -
Lockfile verification now checks the tarballs inside a
variationsresolution against the registry. Aname@versionlockfile entry with an emptyvariationsresolution is now rejected. -
pnpm audit signaturesnow verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification. -
pnpm installandpnpm publishnow reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB. -
Two URL or local path dependencies no longer share a virtual store directory when one URL has
+,#,:, or?where the other has/. Such dependencies, including git dependencies pinned with#, now get a hash suffix on their directory name. -
The warning about an ignored project
.npmrcregistry setting no longer prints the username and password of a URL-scoped key such as//user:password@registry.example.com/${PATH}/:_authToken.
Installing and resolving dependencies
-
pnpm installnow fails withERR_PNPM_UNSUPPORTED_PROTOCOLwhen a dependency uses a specifier with a protocol pnpm does not support, such as Yarn'spatch:. On Windows, such a specifier failed withos error 123. On other platforms, pnpm linked it to a directory that does not exist. Reading apackage.jsonthat fails now names the file #16590. -
pnpm installnow fails withERR_PNPM_PACKAGE_MANIFEST_INVALID_ATTRIBUTEwhen a project declares a dependency whose specifier is not a string, such as"is-positive": 42. Before, the dependency was silently left out of the lockfile. AreadPackagehook can still correct the specifier. -
Fixed
pnpm installfailing withERR_PNPM_CMD_SHIM_RESOLVE_PATHwhen an executable's parent directory contains a dangling symlink. -
pnpm install --frozen-lockfileno longer fails withERR_PNPM_RESOLUTION_SHAPE_MISMATCHwhen aname@versionlockfile entry has a resolution served by a custom fetcher pnpm/tasks#108. -
pnpm install --fix-lockfilerepairs a lockfile whose importer references a package that has no snapshot entry, as left by a badly merged lockfile. It failed withERR_PNPM_LOCKFILE_MISSING_DEPENDENCYsince 12.8.0 #16618. -
When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before,
pnpm installandpnpm dedupekept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies ofvuepnpm/tasks#61. -
pnpm dedupenow reads registry metadata for a dependency pinned to an exact version, aspnpm installdoes. If the registry metadata disagreed with the package'spackage.json, the lockfile it wrote depended on whetherminimumReleaseAgewas set #16615.
Speed and size
-
Dependency resolution reads cached registry metadata faster. The metadata cache moved to
<cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when--offlineis set.pnpm cache prunealso removes the metadata cache that older pnpm versions wrote under<cache-dir>/v11/#13512. -
Package metadata requests no longer wait behind queued tarball downloads when
maxSocketsor a proxy limits the connections to a registry. Large installs resolve faster and print fewerRequest tookwarnings. -
Sped up installs in large workspaces on macOS when the dependency links already exist. pnpm now keeps a link that already points at the right package without trying to create it first. Relinking the direct dependencies of 1,000 workspace projects took 45 ms, down from 116 ms pnpm/tasks#65.
-
Commands in a project that pins a different pnpm version start about 13 ms faster on macOS. pnpm now runs the pinned version's binary directly, without the shell script in front of it pnpm/tasks#66.
-
The pnpm binary is about 0.9 MB smaller, and the arm64 Linux binary is about 1 MB smaller still.
Running scripts and commands
-
pnpm runno longer prints[ELIFECYCLE] Command failed ...after Ctrl+C ends the script. pnpm still exits the way the script's shell did: on Windows with the shell's exit code (cmdreports-1073741510, PowerShell1), on Unix by re-raisingSIGINT#16579. -
pnpm run "/<regex>/"now accepts JavaScript regular expression syntax such as lookahead and lookbehind. A selector like"/^hello:(?!b).*$/"failed withERR_PNPM_NO_SCRIPT#16604. -
pnpm runandpnpm execnow forward--config.*command-line flags to the install started byverifyDepsBeforeRunpnpm/tasks#60. -
On Windows, a process started by
pnpm runorpnpm execcan again start a child withCREATE_BREAKAWAY_FROM_JOB. That child keeps running after pnpm exits, even if the command fails #16628. -
Empty
nodeOptionsvalues from command-line flags and environment variables now override lower-priority settings. Scripts retainNODE_OPTIONSfrom the parent environment orextraEnvwhennodeOptionsis empty. -
pnpm now reads the
failIfNoMatchsetting frompnpm-workspace.yaml, so a filter that matches no workspace project exits with code 1 when the setting istrue. The new--no-fail-if-no-matchflag turns the setting off for one command #16577.
Configuration, setup, and pnpm versions
-
pnpm config get --globalandpnpm config list --globalnow show only the global configuration, also when run inside a project. Settings from the project'spnpm-workspace.yamland.npmrcwere included before. The same applies to--location=global#16598. -
pnpm now prints config warnings, such as an unset environment variable in
.npmrc, when loading the config fails. -
pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the
packageManagerfield pins it. Since 12.9.0 they failed withSyntaxError: Invalid or unexpected token#16594. -
On Windows,
pnpm self-updateno longer runs the update a second time when it replaces apnpm.cmdlinked by pnpm 12.8 or older. cmd.exe read on in the replacedpnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #16573. -
pnpm setupnow puts$PNPM_HOME/binfirst onPATHin login shells that inherited it further down, such as the VS Code terminal on macOS. Before, anothernodetook precedence over the one installed bypnpm runtime set node -g. Runpnpm setupagain to update the block in your shell config #16635. -
pnpm setupnow names the shell config file even if it is already up to date #16608.
Updating, auditing, and publishing
-
pnpm update --latestnow applies thesavePrefixsetting when it rewrites a dependency whose range has no operator of its own, such as<2.0.0. -
The interactive
pnpm audit --fixpicker now shows each patched version with thesaveExactandsavePrefixstyle that the override is written with #13209. -
pnpm unpublish <pkg>@<version>now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #16568. It also no longer mistakes a sibling path such as/npm-mirror/for the registry path/npm/pnpm/tasks#94.
Output and messages
-
A warning about a project's
devEnginesorpackageManagerpin is now printed to stderr. A command such aspnpm cache pathorpnpm list --jsonkeeps only its own output on stdout #16584. -
pnpm listnow reports the correct package paths whennodeLinkerishoisted#9593. -
Resolution errors now name the failing dependency and its parent packages. Fatal errors appear as structured error records with their error codes when using
--reporter=ndjson. -
The error for an invalid git repository in the lockfile now has the code
ERR_PNPM_INVALID_GIT_REPOSITORY. Its message now lists every rejected form of the value. -
pnpm runtime --helpandpnpm help runtimenow name thesetsubcommand and the runtimes it accepts #16580.
Platinum Sponsors
|
|
|
|
|
|
Gold Sponsors
|
|
|
|
|
|
|
|
|
|
|