Fast, disk space efficient package manager Sponsor us: GH: github.com/sponsors/pnpm OC: opencollective.com/pnpm We don't endorse any memecoins!

In the next version of pnpm you'll be able to run the Rust engine for fetching, importing, and linking packages.
7
15
446
22,112
pnpm retweeted
pnpm lead maintainer @zkochan joined PodRocket to talk about pnpm 11: the 24-hour install rule, the new allow-builds config, the global virtual store, and what's coming in v12... including the highly anticipated Rust rewrite.
2
3
10
2,141
pnpm retweeted
The Rust rewrite of pnpm was moved to the pnpm repository today. Now we will make changes to the TS and Rust versions in parallel.
25
47
866
141,208
Hurrah! The pnpm repo has 3K stars on GitHub🎉
5
4
233
The pnpm repository has 34K stars!
1
46
9,702
The pnpm repository has 35K stars!
3
39
6,632
Replying to @pnpmjs
Exact methodology, more stats, history and source on working branch here: github.com/wojtekmaj/package…
2
5
2,265
By some metrics pnpm is currently the most used package manager. However, we know that there is no time for rest. We work on big changes in a few areas to stay relevant.
Replying to @zkochan @pnpmjs
1. Sincerest apologies, underestimated pnpm in my stats because of /npm/.match(…) 🤦 2. Weighted by monorepo it gets interesting! 👇 Please note: this includes ~9k packages from DefinitelyTyped, but even adjusting for this, pnpm would be... #1!
7
13
292
26,620
pnpm retweeted
in times like these, I'm very happy that @sanity_io put some of our @ThePledge dollars on the good folks at @pnpmjs 🫡 (and we made it our mandated package manager internally)
2
4
2,349
Is there anything else we can/should do on the client side to mitigate supply chain attacks?
89
30
877
195,854
It appear pnpm was actually involved in the other side of the story:
Here's an idea. Instead of the 'never let a good crisis go to waste' approach. Go and do an extensive post-mortem of exactly what happened. Because PNPM was the primary tool used in the compromised workflows.
1
46
17,334
The TanStack supply-chain compromise is a masterclass in why "trusted publishing" isn't enough. 🧵
16
42
324
40,133
pnpm retweeted
This is why @pnpmjs's latest v11 release was the top story in Socket Weekly this past week - it includes smart defaults that put roadblocks in front of attacks like this. Hard to imagine a more relevant release for this week’s supply chain chaos. 🔮 socket.dev/blog/pnpm-11-adds…
Everyone is tweeting out "use pnpm & set a minimumReleaseAge of 7 days" but don't forget blockExoticSubdeps - which would also prevent the usage of a remote github reference here!
4
67
504
79,505
pnpm v11.0.6 is out! To update, run: pnpm self-update latest-11
2
9
174
7,984
pnpm retweeted
🧊 Big release for #JavaScript supply chain security: @pnpmjs 11 now defaults to a 1-day Minimum Release Age, blocks exotic subdependencies, and adds a new Allow Builds model. A strong step toward reducing exposure to fast-moving npm attacks → socket.dev/blog/pnpm-11-adds… #nodejs
5
37
137
15,456
Thanks to early feedback we have shipped several fixes. pnpm v11.0.3 is released.
1
3
140
6,798