pnpm 12.8.2 fixes a startup crash on Linux ppc64le and UnknownIssuer errors on systems without CA certificates. pnpm run no longer installs before every script on CI when autoDedupe is enabled, and resolution and hoisted installs on macOS are faster.
Patch Changes
Platforms and environments
-
Fixed pnpm crashing on startup on Linux ppc64le #16380.
-
Fixed installs failing with
UnknownIssueron Linux systems without CA certificates, such asnode:24-slim, whenNODE_EXTRA_CA_CERTSis set. The extra certificates now extend the bundled CA roots #16365. -
pnpm now creates its store operation locks and other per-user lock files in
$XDG_RUNTIME_DIRwhen it points to a directory only the user can write to. Otherwise, pnpm still uses/tmpon Linux and macOS. Sandboxes that block writes to/tmpcan pointXDG_RUNTIME_DIRat a writable directory #16390. -
POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377. -
In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.
Installing and resolving dependencies
-
pnpm install --frozen-lockfilenow fails whenCargo.lockdoes not satisfy a dependency requirement inCargo.toml. The error names the crate and the version the lockfile holds #16355. -
pnpm installreturns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again. -
With
injectWorkspacePackages: true, a freshpnpm installnow records a workspace dependency aslink:when its injected copy differs from the project only by an optional peer that peer-dependent dedupe merges. It was recorded as a peer-suffixedfile:copy #16354. -
pnpm dedupe --checknow passes right afterpnpm dedupewhen deduplication merges variants of a package that differ only in their peers. A lockfile key whose peer suffix named a merged variant now names the variant that replaced it #16356. -
When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. Before, while a new1.0.0was too new,latestfell back to an old0.0.1even though1.0.0-beta.4had beenlatestuntil then #16388. -
Git-hosted dependencies now respect
pmOnFail. If it is set to anything other thandownload, a git-hosted dependency that pins a pnpm version is prepared by the running pnpm, and pnpm does not download the pinned version #16376. -
pnpmfile hooks such as
readPackagenow run once for a dependency that several packages request at the same time. They could run twice for it before. -
childConcurrencynow defaults to 5, the documented value. It used to be capped at 4 and to follow the host's CPU count.
Running scripts
-
pnpm runandpnpm execno longer install dependencies before every script on CI whenautoDedupeis enabled.pnpm install --frozen-lockfilenow keeps the deduplication record left by an earlier install #16374. -
On macOS and Linux, lifecycle scripts and
pnpm runnow always getPATHfrom thePATHvariable. When the environment also held aPathvariable, a script sometimes gotPath's value, and failed withnode: not found#16308. -
pnpm runnow exits after aSIGTERMin a container where pnpm is PID 1 and the script runs pnpm again, as"start": "pnpm serve"does. Since 12.6.0 it kept waiting after the script had shut down, until the container runtime killed it.
Other commands and settings
-
pnpm config get globalShims,pnpm shim list, and global installs no longer readglobalShimsfrom a project'spnpm-workspace.yaml. Only the global config file, the pnpm home's ownpnpm-workspace.yaml, andPNPM_CONFIG_GLOBAL_SHIMSset it, so a repository cannot choose which globally installed packages get project-aware shims. -
pnpm config set --location=projectrefuses a machine-level setting such asstateDirorscopewithERR_PNPM_CONFIG_SET_NOT_A_PROJECT_SETTING, which names where the setting belongs.pnpm config deletestill clears such a key from a project'spnpm-workspace.yaml. -
pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package lists its peer dependency as a dev dependency too #16375. -
pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403. -
pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704. -
pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used. They were left in the store until the nextpnpm store prune#16383.
Performance
-
Sped up dependency resolution in large workspaces, and when many dependencies request different ranges of the same package. Resolution also uses less memory.
-
Sped up
pnpm installwithnodeLinker: hoistedon macOS when the lockfile is re-resolved, such as withautoDedupeenabled #16397. -
Sped up extracting package tarballs.
-
pnpm installwithout--frozen-lockfileis faster on some machines in projects with apnpm-workspace.yaml. Those installs linked with one worker thread per core, half of what a frozen install uses. -
On Windows, warm
pnpm install --frozen-lockfileruns are 4-5% faster on 4- and 8-core machines. pnpm now links with one worker thread per core on Windows, between 4 and 16. This changes frozen installs and installs in projects without apnpm-workspace.yamlon machines with 3 to 15 cores.
Platinum Sponsors
|
|
|
|
|
|
Gold Sponsors
|
|
|
|
|
|
|
|
|
|
|