Fast, disk space efficient package manager Sponsor us: GH: github.com/sponsors/pnpm OC: opencollective.com/pnpm We don't endorse any memecoins!

Yet another reminder to use @pnpmjs's minimum dependency age‼️ pnpm.io/settings#minimumrele…
🔥 New npm attack DETECTED! A campaign dubbed “Sha1-Hulud: The Second Coming” has compromised hundreds of packages and over 25,000 GitHub repos. The code runs during install, steals cloud logins, and if that fails, it deletes the user’s home folder. Read more ↓ thehackernews.com/2025/11/se…
1
5
4
2,674
Maintaining a CLI app? You can now target only the latest Node.js version — pnpm will install it automatically as a dependency for your app.
Replying to @pnpmjs
🧩 Node.js runtime installation for dependencies pnpm can now automatically install the Node.js version required by a dependency, declared in its engines.runtime field. Example:
3
3
78
17,265
We have discovered that chokidar has switched off provenance a year ago and now it fails with the trustPolicy setting set to no-downgrade. We'll need to think about a way to deal with these cases.
Replying to @pnpmjs
A new setting, trustPolicy, adds protection against supply-chain attacks. When set to no-downgrade, pnpm will fail installation if a package’s trust level drops — e.g. from a trusted publisher → provenance only → no trust evidence.
4
2
44
8,090
🎯 In short: Safer installs 🛡️ Smarter runtime management ⚙️ Upgrade to pnpm v10.21: pnpm self-update Full changelog 👉 pnpm.io/blog/releases/10.21
11
2,068
This feature helps detect and block potentially compromised releases, such as when a package’s maintainer changes or its build pipeline loses attestation.
1
10
2,111
A new setting, trustPolicy, adds protection against supply-chain attacks. When set to no-downgrade, pnpm will fail installation if a package’s trust level drops — e.g. from a trusted publisher → provenance only → no trust evidence.
2
9
35
14,059
If a package is a CLI app, pnpm will bind that CLI to the specified Node.js version — so it always runs with the compatible runtime, regardless of what’s installed globally. Even postinstall scripts will be executed with the right Node.js version.
1
11
880
🧩 Node.js runtime installation for dependencies pnpm can now automatically install the Node.js version required by a dependency, declared in its engines.runtime field. Example:
2
4
28
10,937
🚀 pnpm v10.21 is out! This release introduces two powerful new security & compatibility features: 1️⃣ Automatic Node.js runtime installation for dependencies 2️⃣ Configurable trust policy for detecting supply-chain downgrades 🧵👇
1
9
74
6,316
💖 This Sep & Oct, we have forwarded our Open Collective fund to support @chris_zyyv @webfansplz @bluwyoo @KazariEX_0929 @vida_0905 e18e.dev esm.sh @pnpmjs @iconify_design Join us to show appreciation for our deps and help them be sustainable! opencollective.com/antfu/upd…
4
12
107
30,095
pnpm 10.20 is out. Published via a trusted github action using OIDC.
5
12
469
28,862
The pnpm repository has 33K stars!
5
2
86
10,851
Surprisingly, none of the package managers are published using OIDC publishing today. Even npm CLI. I did configure OIDC publishing for @pnpmjs, so it will be "trusted" in the next version
1
1
33
3,655
pnpm v10.19 is out! pnpm.io/blog/releases/10.19
7
37
3,769
I remember using CKEditor at JustAnswer and being really excited when they were considering pnpm years ago. They decided not to switch back then — feels good to win them over at last.
It's impressive to see how quickly @pnpmjs added support for "minimal dependency age" (github.com/pnpm/pnpm/issues/…) after the recent supply chain attacks on npm 😍 By a total coincidence, just a month ago, we finished a migration to pnpm. We definitely don’t look back 🚀 And today, @filipsobol announced that we’ve set a minimum dependency age in our setup, complementing other improvements our platform team has introduced over the years (like pinned deps and package locks). If you're using pnpm, make sure to configure minimumReleaseAge: pnpm.io/settings#minimumrele…
1
2
11
3,282
This is nice. We did not have to make any changes on our side to make this work
Works flawlessly with pnpm!
2
6
30
4,659
You can still vote
Should pnpm delay installation of package versions released less than a day or week ago?
2
1
14
4,687
pnpm retweeted
. @pnpmjs is a strong option for protecting against supply chain attacks, and the DX is excellent too they removed postinstall scripts a while back, cutting one big attack path now they’ve introduced `minimumReleaseAge` which lets you hold off on new versions for a day or more
This is not over. 👇 🚨 A new wave of the npm supply chain attack just hit again. This time targeting CrowdStrike packages. Socket detected malware-laced updates that steal developer creds, spin up rogue GitHub Actions, and exfiltrate secrets. Developing story...
11
34
324
28,248