chore(deps): update pnpm to v11 - #235
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
from
June 2, 2026 11:29
dba5cdd to
9376179
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
4 times, most recently
from
June 12, 2026 02:05
ac6593b to
063e4c3
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
2 times, most recently
from
June 18, 2026 18:47
aa6e886 to
219a986
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
from
June 23, 2026 17:51
219a986 to
41eed40
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
3 times, most recently
from
July 11, 2026 14:59
2c5684b to
8ced8a7
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
5 times, most recently
from
July 19, 2026 02:35
57dcfc5 to
568f156
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
6 times, most recently
from
July 26, 2026 21:04
2337d93 to
a7a4bbf
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
3 times, most recently
from
August 6, 2026 17:29
afb8cef to
ed84b4c
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
3 times, most recently
from
August 18, 2026 19:56
6dc8947 to
9549ef9
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
3 times, most recently
from
September 1, 2026 19:16
58b6ba7 to
1806fda
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
2 times, most recently
from
September 16, 2026 02:00
7fd2dfa to
c06b3ea
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
2 times, most recently
from
September 28, 2026 19:31
6aff3d9 to
9f37b68
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
from
October 1, 2026 18:05
9f37b68 to
aa05b7c
Compare
renovate
Bot
force-pushed
the
renovate/major-11-update-pnpm-version
branch
from
October 1, 2026 22:17
aa05b7c to
acc917e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
10.33.3→11.28.2Release Notes
pnpm/pnpm (pnpm)
v11.28.2: pnpm 11.28.2Compare Source
pnpm 11.28.2 fixes
pnpm installskipping every workspace project whose common ancestor is the filesystem root, and stopspnpm runfrom reinstalling or installing when nothing needs it.Patch Changes
pnpm installreported success without installing anything when the workspace projects' common ancestor was the filesystem root, such as/or a drive root likeC:\. It now installs these projects #16328.verifyDepsBeforeRunno longer reports dependencies as outdated after a filtered install just becausepnpm-lock.yamlhas a newer modification time. It checks the lockfile against the packages that install put in place. Before,pnpm runreinstalled the whole workspace with lifecycle scripts on, for example after a DockerCOPYbrought in a lockfile with a newer mtime #16322.After a filtered install,
verifyDepsBeforeRunnow also checks that the install put the selected projects' dependencies in place. Anode_modulesdirectory alone no longer counts as proof.pnpm runandpnpm execno longer install a project that has never been installed and has nothing to install. Such a project declares no dependencies, no peer dependencies thatautoInstallPeerswould fetch, and no install lifecycle scripts. The command now runs without writingnode_modulesorpnpm-lock.yaml#16313.Platinum Sponsors
Gold Sponsors
v11.28.1: pnpm 11.28.1Compare Source
pnpm 11.28.1 makes
pnpm installwork in StackBlitz WebContainers, repairs lockfiles whose patch hashes disagree withpatchedDependencies, and fixes many bugs in Windows command shims, injected workspace dependencies, andpnpm deploy.Patch Changes
Installing packages
pnpm installnow works in StackBlitz WebContainers. On projects without a lockfile, it used to fail withENOENT ... pnpm-lock.yaml, because pnpm did not recognize the errors that WebContainers return from asynchronous file system calls. It also failed with "this.db.exec is not a function", becausenode:sqlitethere lacksDatabaseSync.exec. Whennode:sqlitecannot prepare statements either, pnpm stores the index inindex.fallback#15649.pnpm installnow completes after downloading a Node.js runtime specified bydevEngines.runtimewhen pnpm runs on Node.js 24.4.x #14667.pnpm installno longer fails when a package from the registry declares afile:dependency on a directory inside itself, such as"@types/css-tree": "file:./typings/css-tree". pnpm links that dependency to the directory inside the package, as npm and Yarn do. The lockfile records it aslink:<root>/typings/css-tree#9141.Installing a git-hosted dependency that has to be built no longer fails when that dependency's own dependencies have build scripts nobody approved. pnpm skips those builds while preparing the dependency, as it does without
strictDepBuilds#9764.pnpm now uses pnpm to prepare a git-hosted dependency that is a pnpm workspace without a committed lockfile. It used npm before, which could skip the dependency's build #14011.
When installing a git dependency over SSH fails with
Permission denied (publickey), pnpm suggests checking the loaded keys withssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewrite that leaves the recorded URL alone #13743.pnpm install --devandpnpm fetch --devnow install the optional dependencies of devDependencies, such as the platform binaries of Biome and oxlint. The project's ownoptionalDependenciesare still skipped #9678.pnpm install --frozen-lockfilenow works on a detached HEAD whengitBranchLockfileis enabled. The install now reads the lockfiles of the local and remote-tracking branches that contain the checked-out commit. It still writes the sharedpnpm-lock.yaml#7672.pnpm installon CI now fails on an outdated lockfile whenpreferFrozenLockfileis explicitly set totrue. Setting it totrueused to let CI update the lockfile #9072.pnpm installnow fails withERR_PNPM_IGNORED_BUILDSon a repeat install whenstrictDepBuildsis on and a dependency's build is still undecided. A repeat install against an existingnode_modulesreported success where a fresh install failed #10450.pnpm installnow removes an optional dependency fromnode_modulesif its install script fails. Code that checks whether the package is installed no longer finds a package that cannot load #8756.pnpm install --offlineandpnpm add --offlinenow resolve a version range to the newest matching version whose tarball is already in the store. They used to pick the newest version in the cached metadata and fail withERR_PNPM_NO_OFFLINE_TARBALLwhen its tarball was missing #10715.If an offline install fails because the registry metadata cache uses the layout from before pnpm 11.27 and 12.4, the error now names the older mirror on disk and explains that one online install repopulates the cache #15656.
pnpm installnow fails right away when writing package files fails because the store is full. It no longer retries the tarball download first #8581.With
nodeLinker: hoisted,pnpm installnow restores a workspace project'snode_modulesafter it was deleted. Before, the install printed "Already up to date" and left the project without the dependencies nested under it.Under
nodeLinker: hoisted,pnpm installnow clears orphaned package directories that an interrupted or failed install leaves in a project'snode_modules. A directory recorded by the previous install is removed, while an unrecorded directory is moved tonode_modules/.ignored. A copy already in.ignoredis never overwritten #13676.Packages in an external
virtualStoreDircan resolve the project's direct dependencies selected byhoistPattern. Runpnpm install --forceto repair an existing installation #5652.A repeat install now keeps the fast path when a declared local file dependency is replaced by an override #12892.
Store, build cache, and global virtual store
Files imported from the store now follow the umask of the install that writes them. Installing with a umask of
077no longer leaves imported files readable by the group and others #3807.With the global virtual store,
pnpm rebuildno longer modifies packages shared with projects that have not approved their build scripts #12302.The side-effects cache now restores the symlinks that a build script creates inside a package. A warm install used to replace each of them with a copy of its target #12859.
After upgrading, every package with a build script is built once more.
pnpm installnow restores cached build artifacts when reinstalling a workspace that uses separate lockfiles #12942.The global virtual store and the side-effects cache now key built packages by the Node.js version that the root project's
devEngines.runtimeorengines.runtimepins. That is the Node.js their build scripts run with. A dependency that declares its ownengines.runtimeno longer changes the key for every other package.Concurrent installs that share a global virtual store now run a package's build in its shared slot one at a time. A failed build leaves the slot in place and marks it for the next install to rebuild #15568.
Concurrent installs no longer fail when they replace the same stale hoisted dependency link. Virtual store cleanup now keeps the temporary lockfiles that concurrent installs are still writing.
pnpm installkeeps the owner, group, and mode of files already in a shared store, includingindex.db. New store files and directories inherit the store directory's group-write bit. When that directory is setgid, new files inherit its group. pnpm does not change a file's owner or group #12765.When
pnpm installrepairs a store file that was modified through a hard link innode_modules, the repair now keeps the file's inode on Linux and macOS. Hard-linked copies in other projects are healed at the same time. Before, only the project running the install received the restored content. On Windows the repair still replaces the file, so other projects are healed on their next install #3445.A tarball whose integrity pnpm computed during download is now found in the store on the next install. Before, that install downloaded the tarball again once the lockfile recorded the integrity #12562.
pnpm now warns when it cannot hard link packages from an existing store in the pnpm home directory and uses a store on the project's filesystem. This can happen when the project is on another filesystem, such as a bind-mounted workspace in a container. The warning names both stores and suggests setting
storeDir#14505.Resolving and linking dependencies
A peer dependency no longer resolves to two different versions for one package. This happened when the package peer-depends on another package and on one of that package's peers, and it is installed deeper than a direct dependency of the package that provides them #12098.
An optional peer dependency is no longer resolved from another workspace project's package when the project provides one of that package's own peers at a version it rejects. This avoids bogus unmet peer errors #13989.
pnpm no longer reports unmet peer dependency warnings for aliased
npm:peer ranges that a tarball dependency satisfies #11126.pnpm installnow links the executables of auto-installed peer dependencies into the workspace root'snode_modules/.bin, including after a frozen-lockfile reinstall #8511.With
resolutionMode: time-basedandminimumReleaseAgeboth set,pnpm installno longer reports a subdependency as too new when only the time-based cutoff excludes it. Such subdependencies used to fail a strict install withERR_PNPM_NO_MATURE_MATCHING_VERSION, or were added tominimumReleaseAgeExclude#13569.A transitive dependency that has no matching version published before the time-based cutoff now resolves to the lowest matching version allowed by
minimumReleaseAge. pnpm picks a version younger thanminimumReleaseAgeonly if no older version matches #16298.With
minimumReleaseAgeset, re-resolving the lockfile no longer rewrites thepeerDependenciesrecorded for a package whose version did not change. This happened when the registry metadata of a package differed from thepackage.jsonin its tarball #13988.pnpm no longer revalidates cached registry metadata when the registry sends
Cache-Control: max-age=0,no-cache, orno-store. It downloads the metadata again, so a version newly published to such a registry is visible on the next install #13487.pnpm's built-in package compatibility database no longer applies to a project's own manifest. A project named like a published package, such as
vue-loader, no longer gains dependencies onpnpm installorpnpm update. User-configuredpackageExtensionsstill apply to project manifests #11700.Relative local tarball paths in
pnpm.overrideswithout an explicitfile:prefix are now rebased correctly for workspace packages #11131.pnpm no longer reports
pnpm-lock.yamlas broken when a project depends on a package namedconstructor. A__proto__key in the lockfile is now kept as a plain entry when pnpm reads or writes the lockfile. It no longer replaces the prototype of the objects pnpm builds from it #11028.With
nodeLinker: pnp, a workspace package can now require another workspace package it depends on #3567. On Windows, workspace dependency paths in the generated.pnp.cjsnow use forward slashes.Performance
pnpm now uses less memory when installing a package whose archive is larger than 64 MiB unpacked, and when installing a runtime from a zip archive, such as Node.js on Windows, Deno, or Bun #14164.
A fresh install reusing a warm global virtual store skips reimporting packages whose target directory is already complete #11112.
A warm
pnpm installreuses on-disk package metadata for five minutes when the registry does not send an ETag. Registries that send an ETag, including the public npm registry, still revalidate with a conditional request.pnpm updatestill fetches current metadata #13976.Patched dependencies
pnpm installnow repairs apnpm-lock.yamlwhose(patch_hash=<hash>)dependency paths disagree with itspatchedDependenciesmap, including paths that lack the hash their patch calls for. pnpm previously accepted such a lockfile as up to date and kept the old patched files.pnpm install --frozen-lockfilenow fails on such a lockfile withERR_PNPM_INCONSISTENT_PATCH_HASH. It fails withERR_PNPM_UNCHECKABLE_PATCH_HASHwhen a patch hash in the lockfile is malformed, or when the lockfile lacks the package version or patch entry that the check needs #15336.pnpm installnow fails withERR_PNPM_PATCH_NOT_FOUNDwhen a patch file listed inpatchedDependenciesdoes not exist. It used to fail with a rawENOENTerror and a stack trace #5268.pnpm now fails with
ERR_PNPM_INVALID_PATCHED_DEPENDENCYwhenpatchedDependencieshas an invalid shape or contains a non-string value.engineStrictnow checks the patchedpackage.jsonwhen apatchedDependenciesentry changesengines. A patch that relaxesengines.nodeno longer fails the install against the published range #9603.pnpm patchnow applies the existing patch file to the edit directory of a git-hosted dependency, as it already does for packages from the registry #9699.pnpm patch-commitnow fails with an error whengitcannot be found inPATH. It previously reported that no changes were found #8666.Workspaces and filtering
pnpm installrefreshes injected copies of workspace packages when source projects are rebuilt. Injected copies previously stayed stale untilpnpm install --force#4407.Scripts listed in
syncInjectedDepsAfterScriptsnow update injected dependencies while they run. A watcher on the injected package, such as a dev server, sees each change before the script exits #4410.pnpm installno longer fails for an injected workspace dependency whose package publishes from apublishConfig.directorythat its ownpreparescript builds. The injected copy now picks up that directory oncepreparefinishes building it.pnpm install --frozen-lockfileno longer reports the dependency as outdated while the directory has not been built yet #7811.With
sharedWorkspaceLockfile: false, an injected workspace package that has lifecycle scripts is now hard linked into the projects that depend on it. Before, pnpm left a plain copy, so later edits to the package did not reach those projects #9828.injectWorkspacePackagesnow hard links a workspace dependency declared with a relative path, such asworkspace:../foo, the same way it already does forworkspace:*#10446.pnpm installno longer creates anode_modulessymlink inside thepublishConfig.directoryof a workspace package linked withlinkDirectory. A build tool that cleaned its output directory through that symlink deleted the files of the package's dependencies.pnpm installalso removes a symlink that an earlier install left there #16226.When
verifyDepsBeforeRuntriggers an install before a filteredpnpm runorpnpm exec, pnpm now installs only the selected projects and their dependencies. A later filtered command also installs a selected project that an earlier filtered install skipped #11865.pnpm importin a workspace now keeps the versions pinned by ayarn.lockinside a workspace project #4385.Installing with
pnprServerset now records the pnpmfile checksum in the lockfile, so a laterpnpm install --frozen-lockfileaccepts that lockfile. A frozen install through the pnpr server now fails if the pnpmfile changed. If the pnpmfile defines areadPackage,afterAllResolvedorpreResolutionhook or custom resolvers, pnpm resolves dependencies locally and prints a warning that the pnpr server was not used #14460.Installing through a pnpr server now links a workspace project at the directory its
publishConfig.directorynames. An install that resolves through a server which does not forward the setting fails withERR_PNPM_PNPR_PUBLISH_DIRECTORY_MISMATCH. The server rejects apublishConfig.directorythat points outside its project.Adding, updating, and removing dependencies
With
autoInstallPeers,pnpm addandpnpm removein a workspace project keep the locked version of a peer dependency the project declares. In a workspace where another project depended on a different version of that package, the peer could switch to that version #11225.Adding a dependency now keeps unrelated transitive dependencies on their locked versions #11456.
pnpm update --recursive <pkg>no longer changes the version of a peer dependency that another workspace project installs automatically. Such a peer could move to a version outside the range the project declares, for example to React 19 in a project that declaresreact: ^18.3.1#14928.pnpm update package@betaon a dependency declared ascatalog:now updates the catalog entry and keepscatalog:inpackage.json. Before, pnpm wrote the resolved specifier topackage.json#13399.pnpm updatenow applies an override that references a catalog with the catalog's new value when the update bumps that catalog entry. Before, the packages the override targets kept the old version in the lockfile #12159.pnpm add <dir>now warns when the added directory declares peer dependencies, aspnpm linkdoes. The directory is saved as alink:dependency, and its peers are not resolved from the project that adds it. Use thefile:protocol to have them resolved #5523.Running scripts and commands
pnpm runandpnpm execno longer install dependencies automatically when the rootpackage.jsonstill keepsoverrides,packageExtensions,patchedDependencies, orignoredOptionalDependenciesin itspnpmfield. pnpm no longer reads that field, so the install rewrote the lockfile without those settings. The command now fails and asks to move the settings topnpm-workspace.yaml#16278.pnpm runno longer reinstalls dependencies when anode_modulesdirectory installed outside CI is used withCI=true, or the other way around #12337.pnpm no longer hangs after a lifecycle script exits while a process it started in the background keeps the script's output open. pnpm stops reading that output one second after the script exits #5730.
A signal sent to pnpm, such as
SIGTERM, now reaches the pnpm that pnpm switches to because ofpackageManagerordevEngines.packageManager, and the one thatpnpm withruns. The signal used to be dropped, so scripts running under that pnpm never got to shut down #9948.pnpm runexits with the code of a script that handles Ctrl+C and shuts down. A script that finished cleanly is not reported as a lifecycle failure. The commands after it in the same script still run #9945.pnpm runand lifecycle scripts use the configuredscriptShell, including Git Bash on Windows, whenshellEmulatoris also enabled.shellEmulatorstill runs scripts whenscriptShellis not set. Extra arguments passed topnpm runare quoted for the shell that runs the script, so a Windows path stays intact #14719.pnpm -r run /regexp/now honors thetasksdependsOndeclared for each script the selector matches, like running the script by name does. Matched scripts that depend on each other run in order. Each matched script runs once #15596.Commands run from a POSIX shell through a dependency's own
node_modules/.bin, such asnode_modules/vite/node_modules/.bin/esbuild, no longer fail withMODULE_NOT_FOUND#10189.pnpm rebuildwithnodeLinker: hoistedno longer puts one package's parentnode_modules/.bindirectories on thePATHof the packages it builds after it.Publishing, packing, and deploying
pnpm publishnow waits at least 5 minutes for the registry to answer a publish request, like npm. This fixes "409 Conflict - Failed to save packument" errors when the registry is slow to answer #11454.pnpm deploywith a shared lockfile now copies workspace dependencies into the deploy directory, even whenpackageImportMethodis set tohardlink. Previously, their files were hard-linked to the workspace sources, so editing a source file also changed the deployed copy #12176.pnpm deploy --prodno longer fails withERR_PNPM_OUTDATED_LOCKFILEwhen the deployed project declares adevEngines.runtimewithonFail: download. The runtime stays out of the deployednode_moduleswith the rest of the dev dependencies #15703.pnpm deploy --legacyno longer leaves broken links to nested local dependencies of workspace packages #9575.pnpm deployno longer creates extra directories inside the deploy target and workspace projects when using a relative deploy path #10981.Manifests and configuration files
Settings given on the command line, such as
--registryand--store-dir, now take precedence over the values a pnpmfileupdateConfighook sets #14063.An
updateConfighook that returnsregistriesByScopewithout thedefaultor@jsrentry no longer crashes the install withInvalid URL. A missingdefaultkeeps the configuredregistry, and a missing@jsrfalls back to the built-in JSR registry #15619.The hook's
registryand thedefaultentry of itsregistriesByScopenow set one default registry, which installs,pnpm publish, andpnpm loginall use. If a hook changes both,registrywins. A route that is not a string fails withERR_PNPM_INVALID_UPDATE_CONFIG_RESULT.An
updateConfighook in.pnpmfile.cjshas to useconfig.registriesByScope,config.registriesByPrefix, andconfig.registryOptionsByUrl. These registry lookups were renamed in pnpm 11.23.0 fromconfig.registries,config.namedRegistries, andconfig.registryOptions#15620.An async
updateConfighook that resolves toundefinednow fails withERR_PNPM_CONFIG_IS_UNDEFINED, as a synchronous hook that returnsundefinedalready did.pnpm config set --location=projectandpnpm config delete --location=project, run from a package inside a workspace, now write settings that belong inpnpm-workspace.yamlto the workspace root'spnpm-workspace.yaml. Before, they created a newpnpm-workspace.yamlin the current package, which made that package the workspace root. Settings stored in.npmrcare still written to the current directory #13757.pnpm now reads the workspace directory override from
PNPM_CONFIG_WORKSPACE_DIR, like other settings.NPM_CONFIG_WORKSPACE_DIRstill works as a fallback #16275.A
${VAR}placeholder in.npmrcorpnpm-workspace.yamlwhose name matches a built-in object property, such as${toString}, is now treated as an unset variable. It used to be replaced with the source text of a JavaScript function.pnpm now rejects a falsy non-array
packagesfield inpnpm-workspace.yaml, such aspackages: false, with an error. It used to treat the field as omitted.Global packages, pnpm versions, and runtimes
pnpm update --globalnow reinstalls the global packages that pnpm 10 installed into the previous global directory,<global-dir>/5, so their commands are linked into the pnpm homebindirectory again andpnpm list --globallists them. Once every package is migrated, pnpm deletes the previous directory and the commands pnpm 10 linked into the pnpm home #11528.pnpm env remove --globaldeletes Node.js versions that pnpm installed into its own store, including when another tool installed pnpm #8357.pnpm self-updateno longer suggests a downgrade whenminimumReleaseAgeholds back the registry'slatestrelease. It now says that release is still within the cutoff #12006.@pnpm/exeno longer ships a binary for arm64 musl Linux, such as Alpine on ARM. The published binary crashed with a segmentation fault at startup. Installing@pnpm/exeon that platform now fails with an error that suggestsnpm install -g pnpmor pnpm 12 #10443.The macOS and Linux release archives no longer include Windows-only files, such as
node-gyp.cmdand thefastlistexecutables #11352.Windows and WSL
On Windows,
pnpm runnow passes the arguments after the script name to the script as typed. Before,cmdexpanded%VAR%in them and backslashes arrived doubled. Line breaks still arrive as the two characters\n, becausecmdcannot pass them. The command line pnpm prints for the script quotes the arguments the same way on every platform #16257.On Windows, command shims now run tools whose paths contain non-ASCII characters #6999. The PowerShell shims do so in Windows PowerShell 5.1 too #16217.
On Windows, the
.cmdcommand shims innode_modules/.binnow keep a%in the project path. Before, cmd.exe expanded it as a variable reference, so the command received a mangledNODE_PATH#15716.Bin shims in
node_modules/.binrun from Cygwin on Windows again. The shims passed a/cygdrive/c/...path to the Windowsnodefound onPATH, so Node.js failed withCannot find module 'C:\cygdrive\c\...'#12845.pnpm setupno longer writes thepn.ps1,pnpx.ps1, andpnx.ps1PowerShell wrappers. It also removes the ones an earlier setup wrote. PowerShell now runspn,pnpx, andpnxthrough their.cmdwrappers, likepnpmitself. Before, these aliases failed with a "not digitally signed" error wherever the execution policy blocks unsigned scripts #8444.On Windows, globally installed
@pnpm/execommands now run in the invoking PowerShell console and return their exit status #6503.On Windows, installing
@pnpm/exewith npm inside a project now writesnode_modules/.binshims that run the standalone executable #15688.On Windows,
pnpm env use -gandpnpm add -g node@runtime:<version>now replace anode.exein the global bin directory that is a broken symlink. Previously they failed withENOENT#5411.On Windows, pnpm expands nested
%VAR%references inPNPM_HOMEand the other directory environment variables it uses for its home, store, cache, state, and config directories. pnpm fails with an error when a%VAR%reference remains after expansion #13236.On Windows, if the global bin directory is not in
PATHand aPATHentry still contains an unexpanded variable such as%PNPM_HOME%, the error now names that entry. A variable referenced from the userPathmust be set to a full path and stored as a plain string (REG_SZ) for the entry to expand #5283.On Windows,
pnpm setupno longer garbles non-ASCII characters in existingPathentries #6346.On Windows,
pnpm setuprepairs thePNPM_HOMEregistry type left by older pnpm versions, even when the configured directory has not changed.On Windows, the
ERR_PNPM_BAD_ENV_FOUNDerror ofpnpm setupnow shows the valuePNPM_HOMEis currently set to. It used to show the directory pnpm wanted to set.On Windows,
pnpm installno longer skips a dependency's build script on a later install when the script changes nothing inside the package directory #15667.On Windows, pnpm now retries writing the workspace state file while another process, such as an antivirus scanner, briefly holds it open #14550.
Inspecting dependencies
pnpm licenses listnow reports the actual on-disk package locations when usingnodeLinker: hoistedorshamefully-hoist: true#8589.pnpm licenses list --jsonnow includes every installed copy of a package in itspathsarray, including hoisted copies and isolated installations with different peer dependencies. Its paths also exist on disk when the isolated linker uses a custommodulesDir.pnpm listnow shows the correct path of alink:dependency that points to a directory on another drive on Windows. The path used to be appended to the project directory, such asC:\project\D:\lib, andpnpm list --longcould not show the package's details #10362.pnpm rootnow prints the configuredmodulesDir. It used to printnode_modulesregardless of the setting. A project's ownmodulesDirfrompackageConfigsis printed too #9113.pnpm auditandpnpm audit signaturesnow fail with an error when the lockfile contains unresolvable dependency references #13638.Output and messages
With the default and append-only reporters, installs with
--loglevel warnor--loglevel errornow print the full output of a failed install script. The output of successful scripts, including the root project's own install hooks, stays hidden. With--loglevel warn, pnpm also prints ignored build script warnings.The lockfile verification error now suggests relaxing the policy that flagged an entry only if a fresh resolution still fails and you trust the affected packages. Errors from checks that no policy controls, such as a missing tarball integrity, no longer suggest relaxing a policy #14411.
pnpm run --recursivenow prints GitLab CI collapsible sections that GitLab recognizes. The section markers used to appear as raw text in the job log.Local tarball dependencies using the file protocol are no longer counted as downloaded in the progress banner #1103.
Platinum Sponsors
Gold Sponsors
v11.28.0: pnpm 11.28Compare Source
pnpm 11.28.0 adds the
forceIgnoresPlatformsetting andpnpm update --peer, and fixes many bugs inpnpm deploy,--filter,nodeLinker: hoisted, and custommodulesDirsetups. This release also carries security fixes for shell completion, bin shims on Nix, lifecycle scripts inside a custommodulesDir, anduserAgentplaceholders inpnpm-workspace.yaml.Minor Changes
forceIgnoresPlatformsetting. When it isfalse,pnpm install --forceskips optional dependencies whoseos,cpuorlibcdo not match the host instead of installing all of them. The default staystrue#6133.Patch Changes
Security
pnpm no longer expands environment variables in a
userAgentset in a project'spnpm-workspace.yaml. AuserAgentwith a placeholder in that file is now ignored. Before this fix, pnpm sent the variable's value to the configured registry #15415.pnpm no longer treats packages inside a custom
modulesDiras workspace projects, including one thatpackageConfigssets for a project. Before, with amodulesDirsuch asvendorand apackagespattern such as**, a repeat install ran the lifecycle scripts of dependencies thatallowBuildshad not approved #15412.On Nix, a dependency's bin named like a system utility such as
sedcan no longer redirect a POSIX bin shim or thepnpm,pn,pnpx, andpnxlaunchers. The shims and launchers now ignorenode_modulesand relativePATHentries while they locate their own files. Installing again replaces the shims already innode_modules#14883.Shell completion now omits candidates containing control or invisible formatting characters, and fish completion omits names containing backslashes. Package and script names can no longer inject extra completion records or terminal escape sequences.
Commands that run pnpm again, such as
pnpm runtime setandpnpm env use, no longer re-run a script that only looks like pnpm. A script namedpnpmorpnthat another package installed was run as though it were pnpm.pnpm store prunenow leaves adlxcache root that is a symlink or Windows junction untouched. Cleanup no longer removes directories through that link.Installing packages
pnpm installnow fails at once when a registry or tarball server presents a TLS certificate that fails verification, such as a self-signed or expired one. The error names the certificate problem. Such requests were retried for more than a minute #9134.pnpm installno longer appears to hang when a git dependency is fetched over SSH and ssh asks for a key passphrase or a host key confirmation. pnpm now runs ssh in batch mode, so the install fails right away with the ssh error, and a key that needs a passphrase has to be loaded into an SSH agent first. An ssh command selected throughGIT_SSH_COMMAND,GIT_SSH, or thecore.sshCommandgit setting is kept as is #2227.pnpm no longer crashes on startup when the temporary directory set by
TMPDIR,TEMP, orTMPdoes not exist #4960.pnpm install --silentno longer fails when the install is delegated to pacquet. pnpm also stops passing-s,--logleveland the other reporting flags to pacquet #11936.Fixed
pnpm installfailing withEEXISTwhen a concurrent install cleared the file or directory that was occupying a symlink path. On Windows, a symlink another process is still holding is no longer moved aside and recreated.pnpm installno longer fails when writing the workspace state file encounters an error. Failures to update the state file now emit a warning instead of aborting the install #14550.Installing or adding dependencies no longer fails when a previously installed local tarball file was deleted from disk #8367.
pnpm installnow reads the same local tarball it installs when a dependency's absolutefile:path contains... Such a path could install a different tarball than the one it read, failing withERR_PNPM_TARBALL_INTEGRITY, or fail to resolve at all.pnpm install --frozen-lockfilenow rejects changed local tarballs, even when the previous archive contents are in the store #1889.pnpm addandpnpm installnow support installing bzip2 compressed tarballs #6761.pnpm installnow fetches committed submodules of git dependencies #1470.Interrupting
pnpm installwith Ctrl+C or SIGTERM no longer leaves a temporary lockfile (.pnpm-lock.yaml.*.tmp) behind in the project #1418.pnpm installandpnpm runnow reinstall a single project that was moved or renamed together with itsnode_modules. Before, they reported "Already up to date" while links such as Windows junctions still pointed at the old location #9512.pnpm installnow relinks a direct dependency whose link innode_modulespoints to a missing target. Before, it reported "Already up to date" and left the broken link #9758.pnpm installandpnpm addno longer skip optional dependencies that the Node.js version resolved for adevEngines.runtimerange supports, when the range usesonFail: download. An explicitly setnodeVersionstill takes priority #14628.pnpm installnow uses the running Node.js whendevEngines.runtimedeclares a range withoutonFail: download. Optional dependencies supported by the active Node.js are no longer skipped #15230.pnpm install --engine-strictnow respectsenginesrelaxed byreadPackagehooks in.pnpmfile.cjs#15482.pnpm installnow applies changes to or removal of a globalreadPackagehook when an existing lockfile is present #15136.The project's
.pnpmfile.mjsor.pnpmfile.cjsnow runs after the pnpmfiles of config dependency plugins #9891.A
readPackagehook that sets a dependency range to a value other than a string, such asundefined, now fails the install with an error that names the dependency, the package, and the pnpmfile. Delete the property to remove a dependency #5517.pnpm install --prodand other installs that skipdevDependenciesno longer run thepnpm:devPreinstallscript #7065. They skippreparelifecycle scripts too, as doespnpm installgiven package arguments.pnpm deploydoes not run thepreparescripts of the deployed project #7282.The root project's
preinstallscript now runs before dependencies are resolved and linked. A guard such asnpx only-allow yarncan stop the install before pnpm populatesnode_modules#3760.pnpm install --prod,pnpm fetch --prodandpnpm deploy --prodno longer install a devDependency that is only there to satisfy an optional peer dependency of a production dependency.pnpm list,pnpm why,pnpm licenses,pnpm sbomandpnpm auditleave it out of--prodresults too. The same applies to--dev. A peer that is not optional is still installed and audited #15344.pnpm prune --prodand production installs now prune excluded development dependencies even when lockfile generation is disabled.pnpm fetchnow also installs the pnpm veConfiguration
📅 Schedule: (in timezone Europe/Istanbul)
* 7-9 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.