Repository navigation
chore(deps): update pnpm to v12 - #710
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 11, 2026 20:42
b512165 to
979057d
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 16, 2026 11:03
979057d to
6ffd97d
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 20, 2026 05:59
6ffd97d to
bd5d686
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 24, 2026 01:50
bd5d686 to
ccdb6c0
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 29, 2026 18:34
ccdb6c0 to
dcba3d3
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
October 4, 2026 01:38
dcba3d3 to
0416df9
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
October 5, 2026 00:49
0416df9 to
e454fc5
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
October 7, 2026 18:24
e454fc5 to
bd0fc21
Compare
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
10.18.0→12.10.1Release Notes
pnpm/pnpm (pnpm)
v12.10.1: pnpm 12.10.1Compare Source
This release fixes
pnpm installfailures after anoverrideschange and on a filtered frozen install withcatalogPrune. It also fixes several bugs in the experimentalnodeLinker.type: loaded, which now keeps its generated files innode_modules.Patch Changes
With
nodeLinker.type: loaded, pnpm now writes its generated files tonode_modules, which projects already ignore in git. The store manifest and loader arenode_modules/.pnpm/.store-manifest.jsonandnode_modules/.pnpm/.store-loader.mjs. Bin shims are innode_modules/.bin.Earlier versions wrote
.pnpm-store.jsonand.pnpm-store-loader.mjsto the project root, and a.pnpmdirectory to the root and to each workspace package. Delete them after reinstalling.With
nodeLinker.type: loaded, packages that ship their ownnode_modulesdirectory, such asnpmwith its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.With
nodeLinker.type: loaded, scripts can now run a Node.js runtime installed throughdevEngines.runtime. Before, every script that callednodere-ran its own shim until it failed with "Argument list too long".With
nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.pnpm installno longer fails withERR_PNPM_NO_MATCHING_VERSIONafter a change tooverrideswhen the lockfile resolves an optional peer dependency to an npm alias of another package #16654.A frozen install with
catalogPruneno longer removes catalog entries thatpnpm-lock.yamlstill records. Before,pnpm install --frozen-lockfile --filterfailed withERR_PNPM_LOCKFILE_CONFIG_MISMATCHwhen some workspace projects were missing from disk #16638.pnpm install --fix-lockfileno longer removes thedeprecatedandhasBinfields from lockfile entries #6600.With
enableGlobalVirtualStore, an install that updatesnode_modulesnow repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project'snode_modulesalready recorded it #16642.pnpm installnow skips the Cargo and Python projects inside a nested directory that has its ownpnpm-workspace.yamlor.gitdirectory, such as a git worktree of the same workspace or a separate clone.The
Request tookwarning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.Platinum Sponsors
Gold Sponsors
v12.10.0: pnpm 12.10.0Compare Source
This release adds an experimental
loadednode linker, letspnpm-lock.yamlrecord resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.Minor Changes
Added experimental
nodeLinker: { type: loaded }installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader.nodeLinker.excludedselects packages and their dependency trees to install in the global virtual store.lockfile.includeResolutionSettings: truemakespnpm-lock.yamlrecordautoDedupe,dedupeInjectedDeps,dedupePeerDependentsandlinkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that recordsautoDedupeis reused by later installs on any machine, sopnpm runafterpnpm install --frozen-lockfileno longer starts another install #16583.Patch Changes
Security
pnpm installnow prevents dependency versions with path traversal from writing files outside the global virtual store.pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with
version+integrity.Lockfile verification now checks the tarballs inside a
variationsresolution against the registry. Aname@versionlockfile entry with an emptyvariationsresolution is now rejected.pnpm audit signaturesnow verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.pnpm installandpnpm publishnow reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB.Two URL or local path dependencies no longer share a virtual store directory when one URL has
+,#,:, or?where the other has/. Such dependencies, including git dependencies pinned with#, now get a hash suffix on their directory name.The warning about an ignored project
.npmrcregistry setting no longer prints the username and password of a URL-scoped key such as//user:password@registry.example.com/${PATH}/:_authToken.Installing and resolving dependencies
pnpm installnow fails withERR_PNPM_UNSUPPORTED_PROTOCOLwhen a dependency uses a specifier with a protocol pnpm does not support, such as Yarn'spatch:. On Windows, such a specifier failed withos error 123. On other platforms, pnpm linked it to a directory that does not exist. Reading apackage.jsonthat fails now names the file #16590.pnpm installnow fails withERR_PNPM_PACKAGE_MANIFEST_INVALID_ATTRIBUTEwhen a project declares a dependency whose specifier is not a string, such as"is-positive": 42. Before, the dependency was silently left out of the lockfile. AreadPackagehook can still correct the specifier.Fixed
pnpm installfailing withERR_PNPM_CMD_SHIM_RESOLVE_PATHwhen an executable's parent directory contains a dangling symlink.pnpm install --frozen-lockfileno longer fails withERR_PNPM_RESOLUTION_SHAPE_MISMATCHwhen aname@versionlockfile entry has a resolution served by a custom fetcher pnpm/tasks#108.pnpm install --fix-lockfilerepairs a lockfile whose importer references a package that has no snapshot entry, as left by a badly merged lockfile. It failed withERR_PNPM_LOCKFILE_MISSING_DEPENDENCYsince 12.8.0 #16618.When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before,
pnpm installandpnpm dedupekept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies ofvuepnpm/tasks#61.pnpm dedupenow reads registry metadata for a dependency pinned to an exact version, aspnpm installdoes. If the registry metadata disagreed with the package'spackage.json, the lockfile it wrote depended on whetherminimumReleaseAgewas set #16615.Speed and size
Dependency resolution reads cached registry metadata faster. The metadata cache moved to
<cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when--offlineis set.pnpm cache prunealso removes the metadata cache that older pnpm versions wrote under<cache-dir>/v11/#13512.Package metadata requests no longer wait behind queued tarball downloads when
maxSocketsor a proxy limits the connections to a registry. Large installs resolve faster and print fewerRequest tookwarnings.Sped up installs in large workspaces on macOS when the dependency links already exist. pnpm now keeps a link that already points at the right package without trying to create it first. Relinking the direct dependencies of 1,000 workspace projects took 45 ms, down from 116 ms pnpm/tasks#65.
Commands in a project that pins a different pnpm version start about 13 ms faster on macOS. pnpm now runs the pinned version's binary directly, without the shell script in front of it pnpm/tasks#66.
The pnpm binary is about 0.9 MB smaller, and the arm64 Linux binary is about 1 MB smaller still.
Running scripts and commands
pnpm runno longer prints[ELIFECYCLE] Command failed ...after Ctrl+C ends the script. pnpm still exits the way the script's shell did: on Windows with the shell's exit code (cmdreports-1073741510, PowerShell1), on Unix by re-raisingSIGINT#16579.pnpm run "/<regex>/"now accepts JavaScript regular expression syntax such as lookahead and lookbehind. A selector like"/^hello:(?!b).*$/"failed withERR_PNPM_NO_SCRIPT#16604.pnpm runandpnpm execnow forward--config.*command-line flags to the install started byverifyDepsBeforeRunpnpm/tasks#60.On Windows, a process started by
pnpm runorpnpm execcan again start a child withCREATE_BREAKAWAY_FROM_JOB. That child keeps running after pnpm exits, even if the command fails #16628.Empty
nodeOptionsvalues from command-line flags and environment variables now override lower-priority settings. Scripts retainNODE_OPTIONSfrom the parent environment orextraEnvwhennodeOptionsis empty.pnpm now reads the
failIfNoMatchsetting frompnpm-workspace.yaml, so a filter that matches no workspace project exits with code 1 when the setting istrue. The new--no-fail-if-no-matchflag turns the setting off for one command #16577.Configuration, setup, and pnpm versions
pnpm config get --globalandpnpm config list --globalnow show only the global configuration, also when run inside a project. Settings from the project'spnpm-workspace.yamland.npmrcwere included before. The same applies to--location=global#16598.pnpm now prints config warnings, such as an unset environment variable in
.npmrc, when loading the config fails.pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the
packageManagerfield pins it. Since 12.9.0 they failed withSyntaxError: Invalid or unexpected token#16594.On Windows,
pnpm self-updateno longer runs the update a second time when it replaces apnpm.cmdlinked by pnpm 12.8 or older. cmd.exe read on in the replacedpnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #16573.pnpm setupnow puts$PNPM_HOME/binfirst onPATHin login shells that inherited it further down, such as the VS Code terminal on macOS. Before, anothernodetook precedence over the one installed bypnpm runtime set node -g. Runpnpm setupagain to update the block in your shell config #16635.pnpm setupnow names the shell config file even if it is already up to date #16608.Updating, auditing, and publishing
pnpm update --latestnow applies thesavePrefixsetting when it rewrites a dependency whose range has no operator of its own, such as<2.0.0.The interactive
pnpm audit --fixpicker now shows each patched version with thesaveExactandsavePrefixstyle that the override is written with #13209.pnpm unpublish <pkg>@<version>now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #16568. It also no longer mistakes a sibling path such as/npm-mirror/for the registry path/npm/pnpm/tasks#94.Output and messages
A warning about a project's
devEnginesorpackageManagerpin is now printed to stderr. A command such aspnpm cache pathorpnpm list --jsonkeeps only its own output on stdout #16584.pnpm listnow reports the correct package paths whennodeLinkerishoisted#9593.Resolution errors now name the failing dependency and its parent packages. Fatal errors appear as structured error records with their error codes when using
--reporter=ndjson.The error for an invalid git repository in the lockfile now has the code
ERR_PNPM_INVALID_GIT_REPOSITORY. Its message now lists every rejected form of the value.pnpm runtime --helpandpnpm help runtimenow name thesetsubcommand and the runtimes it accepts #16580.Platinum Sponsors
Gold Sponsors
v12.9.1: pnpm 12.9.1Compare Source
This release moves the WebContainer build into a separate
@pnpm/wasmpackage, shrinks thepnpmpackage back to about 4 MB, and fixespnpm publishwith provenance from GitLab CI.Patch Changes
The WebAssembly build for StackBlitz WebContainers now ships as a separate
@pnpm/wasmpackage. Thepnpmand@pnpm/exepackages no longer include it, which brings their unpacked size back from about 55 MB to about 4 MB. In a WebContainer, install@pnpm/wasmwith npm to get thepnpmcommand.pnpm publishwith provenance from GitLab CI is no longer rejected by the npm registry with a 422 error. The provenance statement now includes the GitLab CI variables ininvocation.parameters, as npm does #16551.pnpm audit signaturesnow uses the TLS settings of the redirect target when a registry redirects its signing-keys request, for example to registry.npmjs.org. Acafilescoped to a private registry no longer makes the redirected request fail #16541.Fixed
pnpm install --frozen-lockfilerejecting an up-to-date lockfile when an injected workspace package uses a catalog entry inpeerDependencies#16557.The
[<since>]filter selector works again with Git 2.24 through 2.27 #16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.It also detects changes in projects whose directory names contain non-ASCII characters. Such a change used to be credited to the parent project.
changedFilesIgnorePatternandtestPatternnow match changed files whose names contain non-ASCII characters.The
pnpmexecutable is about 10% smaller. On macOS arm64 it went from 45.1 MB to 40.3 MB.Sped up trust downgrade checks for packages with long release histories.
With
optimisticRepeatInstall: false,pnpm installnow runs the projects' own lifecycle scripts, such asprepare, even whennode_modulesis already up to date #16545.pnpm self-updatenow fails for Homebrew-installed pnpm and prints thebrew upgradecommand for the installed formula, such asbrew upgrade pnpmorbrew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #16547.Platinum Sponsors
Gold Sponsors
v12.9.0: pnpm 12.9Compare Source
This release runs pnpm in StackBlitz WebContainers, adds a per-registry
networkConcurrencysetting, and records every installed project in the store. It also carries a security fix forpnpm login.Minor Changes
pnpm now automatically uses WebAssembly in StackBlitz WebContainers, including when installation scripts are disabled. Native installations continue to use the native executable when installation scripts are enabled.
A
registriesentry can now setnetworkConcurrency, the most requests pnpm keeps in flight to that registry's origin. Requests to other registries keep the overall limit. The setting may live inpnpm-workspace.yamlor the globalconfig.yaml.pnpm installnow records every project it installs in the store'sprojectsdirectory, as a symlink to the project directory. A--frozen-storeinstall without the global virtual store still records nothing. Only projects that used the global virtual store were recorded before #6929.Patch Changes
pnpm loginno longer forwards credentials in its request body to another origin during redirects.Installing packages
Fixed
pnpm installfailing on Android withERR_PNPM_STORE_DIR_ACQUIRE_OPERATION_LOCK#16508.pnpm install --frozen-lockfileagain succeeds when a workspace project recorded inpnpm-lock.yamlhas no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without apackage.json#16453.pnpm install --frozen-lockfileno longer requires apnpm-lock.yamlin a project that has no dependencies. It also succeeds whenpnpm-lock.yamlrecords only the pinned pnpm version, as other commands write it when they run before the first install #16477.Fixed
pnpm install --frozen-lockfilerejecting a fresh lockfile when an injected workspace dependency has an optional peer supplied by another workspace project #16428.With
nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put innode_modules. This also covers the install thatpnpm --filter <selector> runandpnpm --filter <selector> execstart before the command. Before, these installs removed every package that only the unselected projects needed #16483.pnpm installwithnodeLinker: hoistednow refreshes directories supplied by custom fetchers when reinstalling. pnpm also keeps the symlinks inside those directories.With
enableGlobalVirtualStoreon, scripts can run entry points that a CommonJS require hook loads again, such asts-node index.ts. They failed withERR_UNKNOWN_FILE_EXTENSIONon Node.js versions without built-in TypeScript support #16436.pnpm now keeps each project's current lockfile and hidden hoisted dependencies in its own
node_modules/.pnpmwhenvirtualStoreDirpoints at a shared global virtual store.--virtual-store-dirnow sets the global virtual store's location too pnpm/tasks#47.pnpm cleanno longer deletes the project whenvirtualStoreDirorglobalVirtualStoreDiris set to the project directory. It also leaves a directory outside the project alone when the setting reaches it through a symlink. It now removes a global virtual store thatglobalVirtualStoreDirplaces inside the project, as it does forvirtualStoreDir.Optional dependencies
pnpm installno longer fails when a dependency of an optional dependency is missing from the registry. Like npm, pnpm now leaves out the nearest optional dependency above it, together with its subtree #16511.When an optional dependency fails to build, pnpm now removes its link from
node_modules. A repeatpnpm installthen reports "Already up to date" and no longer reruns the failing build #16468.pnpm installnow prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer counted in thePackages: +Nsummary. Thepnpm:skipped-optional-dependencylog reports the skip with thefetch_failurereason #16514.Resolving dependencies
Fixed
pnpm installchanging an unchanged project's direct dependency to a sibling workspace's pinned version when its dependency tree contains a cycle #16417.With
autoDedupeenabled, downgrading a dependency in one workspace project now moves the other projects to that version when it satisfies their ranges. This also applies to a filteredpnpm --filter <project> add#16432.pnpm installandpnpm dedupenow move an optional peer to the version already in the dependency graph when no other package provides its locked version anymore. After a bump such asvue3.5.40 to 3.5.43, the lockfile kept a second copy of@vue/server-rendererfor@vue/test-utils#16443.pnpm dedupe --checkno longer fails right afterpnpm installwhen a project's optional peer is satisfied by a package another workspace project installs.pnpm dedupenow picks the same versions for that package's dependencies aspnpm install#16447.pnpm installno longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #16418.With
autoDedupeenabled,pnpm install --lockfile-onlyno longer resolves the dependency graph again when nothing changed since an earlier--lockfile-onlyinstall deduplicated the lockfile. Such an install keeps the lockfile even if versions were published since it was written, or if only a setting such asresolutionModechanged. Runpnpm dedupeto apply such a change #16458.Speed and network
A repeat
pnpm installin a large workspace reports "Already up to date" faster #16487.Sped up dependency resolution of workspaces with many peer dependencies.
pnpm installsends fewer registry metadata requests when the lockfile already decides which version a range resolves to. This now also covers ranges that several locked versions satisfy when one of them outranks the others, and direct dependencies kept at their locked version. Packages thatminimumReleaseAgeExcludelists without a version now reuse cached registry metadata the same way they do whenminimumReleaseAgeis not set #16458.pnpm no longer downloads every packument again on each install from a registry whose metadata responses forbid caching, such as
Cache-Control: no-store. pnpm revalidates the cached metadata with a conditional request, so a registry that supports conditional requests answers with a 304 when the package has not changed #16528.Cached metadata for a package published within
minimumReleaseAgeis now revalidated with its ETag, so the npm registry can answer304 Not Modified. Before, the next install that checked the cache downloaded the whole document again #16506.A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #12791.
Sped up
pnpm install --offlinewhen the version a range picks is not in the store. While it looks for a version the store holds, pnpm now reads only the versions the range admits #16495.pnpm install --offlinenow reuses config dependency tarballs that are already present in the store pnpm/tasks#46.Running scripts
pnpm -s <script>runs the script again, with-smeaning--sequentialas it does forpnpm run -s <script>. pnpm rejected it with "unexpected argument '-s' found" #16446.pnpm runandpnpm execnow warn and run the command when the install thatverifyDepsBeforeRunstarts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #15173.A filtered
pnpm runorpnpm execnow finds dependencies out of date when a workspace dependency of a selected project has nonode_modulesdirectory, as after a filtered install. WithverifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.Scripts run without a terminal no longer start a second
sheach. One watchdog per pnpm command now ends every script's process group if pnpm is killed, sopnpm -r runacross many projects starts half as many processes #16489.Terminate batch job (Y/N)?no longer appears after pressing Ctrl+C in a script started withpnpmfrom PowerShell or cmd on Windows #16502.pnpm rebuildandpnpm approve-buildsrefresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.When
pnpm run <script>orpnpm <script>finds nothing to run and--filterfollows the script name, the error now suggests putting the filter option before the script name #4655.Package-name filters now support
?to match one character #2817.The pinned pnpm and
pnpm self-updatepnpm no longer downloads the project's pinned pnpm version again on every command when
nodeVersioninpnpm-workspace.yamlnames a different Node.js major than thenodeonPATH. Before, each of those commands took about a second longer and failed without network access #16497.Several
pnpmcommands started at once in a project that pinspackageManagerno longer fail withThe process cannot access the file because it is being used by another processon Windows while the pinned pnpm is being installed.pnpm can now switch to a
packageManagerversion below 11 on x64 musl Linux, such as Alpine #16467.A
devEngines.packageManagerrange no longer makes pnpm replace the version recorded inpnpm-lock.yamlwith the running pnpm while the recorded version still satisfies the range. When pnpm does record a version, it records the running pnpm only if it meetsminimumReleaseAge. Otherwise it records the newest version in the range that meets it, or the running pnpm if none does #16431.On Windows,
pnpm self-updatenow replaces apnpm.exeleft inPNPM_HOMEor inPNPM_HOME\bin. Windows ran that executable in place of the updatedpnpm.cmdshim, sopnpm --versionkept printing the old version after a successful update. If the executable was inPNPM_HOME,self-updatenow asks you to runpnpm setup#9094.pnpm self-updatenow checks that a version installed as the JavaScriptpnpmcan start before making it the globalpnpm. If Node.js is missing, the update fails and the currentpnpmstays in place.Other commands
pnpm deploynow finds patches and local dependencies when the target directory sits under a symlink, such as/tmpon macOS. It failed withERR_PNPM_PATCH_NOT_FOUND#16470.pnpm deploy --legacynow resolves the deployed project's relativefile:,link:, and path dependencies from the project's own directory #16475.pnpm update --globalnow removes hard-linked executables fromPNPM_HOMEwhen migrating packages from the old global layout #16420.pnpm store pruneno longer fails on store index entries that pnpm 11 wrote for git-hosted packages without apackage.json. Entries that still cannot be read are kept and counted in the prune summary.pnpm store prunenow aborts when an error other than a missing directory occurs while scanning project directories in the mark phase.pnpm config getandpnpm config listnow report a setting given on the command line with--config.<name>=<value>. Before, a value such as--config.node-linker=hoistedreached the install but was absent from the reported configuration #16276.pnpm -r pkg getnow reports every selected project when several share a package name. Projects with the same name are keyed by their directory relative to the workspace root. Before, only one of them appeared in the output.The install summary shows a
link:dependency as+ name <- path, and the Node.js API'shideLinkedPkgsDiffreporter option leaves matching linked dependencies out of the summary.The
--forcehelp text ofpnpm installandpnpm addnow says that--forcekeeps skipping optional dependencies built for other platforms. It points toforceIgnoresPlatformand the--os,--cpu, and--libcoptions for installing them #16435.The
homepagefield of the publishedpnpmpackage points to https://pnpm.io again.Platinum Sponsors
Gold Sponsors
v12.8.2: pnpm 12.8.2Compare Source
pnpm 12.8.2 fixes a startup crash on Linux ppc64le and
UnknownIssuererrors on systems without CA certificates.pnpm runno longer installs before every script on CI whenautoDedupeis enabled, and resolution and hoisted installs on macOS are faster.Patch Changes
Platforms and environments
Fixed pnpm crashing on startup on Linux ppc64le #16380.
Fixed installs failing with
UnknownIssueron Linux systems without CA certificates, such asnode:24-slim, whenNODE_EXTRA_CA_CERTSis set. The extra certificates now extend the bundled CA roots #16365.pnpm now creates its store operation locks and other per-user lock files in
$XDG_RUNTIME_DIRwhen it points to a directory only the user can write to. Otherwise, pnpm still uses/tmpon Linux and macOS. Sandboxes that block writes to/tmpcan pointXDG_RUNTIME_DIRat a writable directory #16390.POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377.In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before, pnpm rejected the option before switching, so
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.Installing and resolving dependencies
pnpm install --frozen-lockfilenow fails whenCargo.lockdoes not satisfy a dependency requirement inCargo.toml. The error names the crate and the version the lockfile holds #16355.pnpm installreturns "Already up to date" again in a workspace with injected workspace dependencies and a shared lockfile. Since 12.7.0 every repeat install in such a workspace ran the full install and copied the injected projects again.With
injectWorkspacePackages: true,