Skip to content

chore(deps): update pnpm to v12 - #710

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pnpm-12.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pnpm-12.x

Conversation

@renovate

@renovate renovate Bot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
pnpm (source) 10.18.0 → 12.9.1 age confidence

Release Notes

pnpm/pnpm (pnpm)

v12.9.1: pnpm 12.9.1

Compare Source

This release moves the WebContainer build into a separate @pnpm/wasm package, shrinks the pnpm package back to about 4 MB, and fixes pnpm publish with provenance from GitLab CI.

Patch Changes
  • The WebAssembly build for StackBlitz WebContainers now ships as a separate @pnpm/wasm package. The pnpm and @pnpm/exe packages no longer include it, which brings their unpacked size back from about 55 MB to about 4 MB. In a WebContainer, install @pnpm/wasm with npm to get the pnpm command.

  • pnpm publish with provenance from GitLab CI is no longer rejected by the npm registry with a 422 error. The provenance statement now includes the GitLab CI variables in invocation.parameters, as npm does #​16551.

  • pnpm audit signatures now uses the TLS settings of the redirect target when a registry redirects its signing-keys request, for example to registry.npmjs.org. A cafile scoped to a private registry no longer makes the redirected request fail #​16541.

  • Fixed pnpm install --frozen-lockfile rejecting an up-to-date lockfile when an injected workspace package uses a catalog entry in peerDependencies #​16557.

  • The [<since>] filter selector works again with Git 2.24 through 2.27 #​16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.

    It also detects changes in projects whose directory names contain non-ASCII characters. Such a change used to be credited to the parent project. changedFilesIgnorePattern and testPattern now match changed files whose names contain non-ASCII characters.

  • The pnpm executable is about 10% smaller. On macOS arm64 it went from 45.1 MB to 40.3 MB.

  • Sped up trust downgrade checks for packages with long release histories.

  • With optimisticRepeatInstall: false, pnpm install now runs the projects' own lifecycle scripts, such as prepare, even when node_modules is already up to date #​16545.

  • pnpm self-update now fails for Homebrew-installed pnpm and prints the brew upgrade command for the installed formula, such as brew upgrade pnpm or brew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #​16547.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.9.0: pnpm 12.9

Compare Source

This release runs pnpm in StackBlitz WebContainers, adds a per-registry networkConcurrency setting, and records every installed project in the store. It also carries a security fix for pnpm login.

Minor Changes
  • pnpm now automatically uses WebAssembly in StackBlitz WebContainers, including when installation scripts are disabled. Native installations continue to use the native executable when installation scripts are enabled.

  • A registries entry can now set networkConcurrency, the most requests pnpm keeps in flight to that registry's origin. Requests to other registries keep the overall limit. The setting may live in pnpm-workspace.yaml or the global config.yaml.

    registries:
      https://npm.corp.example.com/:
        scopes: ["@acme"]
        networkConcurrency: 4
  • pnpm install now records every project it installs in the store's projects directory, as a symlink to the project directory. A --frozen-store install without the global virtual store still records nothing. Only projects that used the global virtual store were recorded before #​6929.

Patch Changes
  • pnpm login no longer forwards credentials in its request body to another origin during redirects.
Installing packages
  • Fixed pnpm install failing on Android with ERR_PNPM_STORE_DIR_ACQUIRE_OPERATION_LOCK #​16508.

  • pnpm install --frozen-lockfile again succeeds when a workspace project recorded in pnpm-lock.yaml has no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without a package.json #​16453.

  • pnpm install --frozen-lockfile no longer requires a pnpm-lock.yaml in a project that has no dependencies. It also succeeds when pnpm-lock.yaml records only the pinned pnpm version, as other commands write it when they run before the first install #​16477.

  • Fixed pnpm install --frozen-lockfile rejecting a fresh lockfile when an injected workspace dependency has an optional peer supplied by another workspace project #​16428.

  • With nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put in node_modules. This also covers the install that pnpm --filter <selector> run and pnpm --filter <selector> exec start before the command. Before, these installs removed every package that only the unselected projects needed #​16483.

  • pnpm install with nodeLinker: hoisted now refreshes directories supplied by custom fetchers when reinstalling. pnpm also keeps the symlinks inside those directories.

  • With enableGlobalVirtualStore on, scripts can run entry points that a CommonJS require hook loads again, such as ts-node index.ts. They failed with ERR_UNKNOWN_FILE_EXTENSION on Node.js versions without built-in TypeScript support #​16436.

  • pnpm now keeps each project's current lockfile and hidden hoisted dependencies in its own node_modules/.pnpm when virtualStoreDir points at a shared global virtual store. --virtual-store-dir now sets the global virtual store's location too pnpm/tasks#47.

  • pnpm clean no longer deletes the project when virtualStoreDir or globalVirtualStoreDir is set to the project directory. It also leaves a directory outside the project alone when the setting reaches it through a symlink. It now removes a global virtual store that globalVirtualStoreDir places inside the project, as it does for virtualStoreDir.

Optional dependencies
  • pnpm install no longer fails when a dependency of an optional dependency is missing from the registry. Like npm, pnpm now leaves out the nearest optional dependency above it, together with its subtree #​16511.

  • When an optional dependency fails to build, pnpm now removes its link from node_modules. A repeat pnpm install then reports "Already up to date" and no longer reruns the failing build #​16468.

  • pnpm install now prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer counted in the Packages: +N summary. The pnpm:skipped-optional-dependency log reports the skip with the fetch_failure reason #​16514.

Resolving dependencies
  • Fixed pnpm install changing an unchanged project's direct dependency to a sibling workspace's pinned version when its dependency tree contains a cycle #​16417.

  • With autoDedupe enabled, downgrading a dependency in one workspace project now moves the other projects to that version when it satisfies their ranges. This also applies to a filtered pnpm --filter <project> add #​16432.

  • pnpm install and pnpm dedupe now move an optional peer to the version already in the dependency graph when no other package provides its locked version anymore. After a bump such as vue 3.5.40 to 3.5.43, the lockfile kept a second copy of @vue/server-renderer for @vue/test-utils #​16443.

  • pnpm dedupe --check no longer fails right after pnpm install when a project's optional peer is satisfied by a package another workspace project installs. pnpm dedupe now picks the same versions for that package's dependencies as pnpm install #​16447.

  • pnpm install no longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #​16418.

  • With autoDedupe enabled, pnpm install --lockfile-only no longer resolves the dependency graph again when nothing changed since an earlier --lockfile-only install deduplicated the lockfile. Such an install keeps the lockfile even if versions were published since it was written, or if only a setting such as resolutionMode changed. Run pnpm dedupe to apply such a change #​16458.

Speed and network
  • A repeat pnpm install in a large workspace reports "Already up to date" faster #​16487.

  • Sped up dependency resolution of workspaces with many peer dependencies.

  • pnpm install sends fewer registry metadata requests when the lockfile already decides which version a range resolves to. This now also covers ranges that several locked versions satisfy when one of them outranks the others, and direct dependencies kept at their locked version. Packages that minimumReleaseAgeExclude lists without a version now reuse cached registry metadata the same way they do when minimumReleaseAge is not set #​16458.

  • pnpm no longer downloads every packument again on each install from a registry whose metadata responses forbid caching, such as Cache-Control: no-store. pnpm revalidates the cached metadata with a conditional request, so a registry that supports conditional requests answers with a 304 when the package has not changed #​16528.

  • Cached metadata for a package published within minimumReleaseAge is now revalidated with its ETag, so the npm registry can answer 304 Not Modified. Before, the next install that checked the cache downloaded the whole document again #​16506.

  • A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #​12791.

  • Sped up pnpm install --offline when the version a range picks is not in the store. While it looks for a version the store holds, pnpm now reads only the versions the range admits #​16495.

  • pnpm install --offline now reuses config dependency tarballs that are already present in the store pnpm/tasks#46.

Running scripts
  • pnpm -s <script> runs the script again, with -s meaning --sequential as it does for pnpm run -s <script>. pnpm rejected it with "unexpected argument '-s' found" #​16446.

  • pnpm run and pnpm exec now warn and run the command when the install that verifyDepsBeforeRun starts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #​15173.

  • A filtered pnpm run or pnpm exec now finds dependencies out of date when a workspace dependency of a selected project has no node_modules directory, as after a filtered install. With verifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.

  • Scripts run without a terminal no longer start a second sh each. One watchdog per pnpm command now ends every script's process group if pnpm is killed, so pnpm -r run across many projects starts half as many processes #​16489.

  • Terminate batch job (Y/N)? no longer appears after pressing Ctrl+C in a script started with pnpm from PowerShell or cmd on Windows #​16502.

  • pnpm rebuild and pnpm approve-builds refresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.

  • When pnpm run <script> or pnpm <script> finds nothing to run and --filter follows the script name, the error now suggests putting the filter option before the script name #​4655.

  • Package-name filters now support ? to match one character #​2817.

The pinned pnpm and pnpm self-update
  • pnpm no longer downloads the project's pinned pnpm version again on every command when nodeVersion in pnpm-workspace.yaml names a different Node.js major than the node on PATH. Before, each of those commands took about a second longer and failed without network access #​16497.

  • Several pnpm commands started at once in a project that pins packageManager no longer fail with The process cannot access the file because it is being used by another process on Windows while the pinned pnpm is being installed.

  • pnpm can now switch to a packageManager version below 11 on x64 musl Linux, such as Alpine #​16467.

  • A devEngines.packageManager range no longer makes pnpm replace the version recorded in pnpm-lock.yaml with the running pnpm while the recorded

❗ Important

✂ PR body was truncated to here.


Configuration and pnpmfile hooks

  • Every setting pnpm supports can now be set with --config.<name>=<value> on the command line, not only the ones whose command also carries a matching flag. Before, pnpm install --config.frozen-lockfile=true dropped the setting and rewrote pnpm-lock.yaml as though the install had not been frozen #​16276.

  • Settings given on the command line, such as --registry and --store-dir, now take precedence over the values a pnpmfile updateConfig hook sets #​14063.

  • pnpm config set --location=project and pnpm config delete --location=project, run from a package inside a workspace, now write settings that belong in pnpm-workspace.yaml to the workspace root's pnpm-workspace.yaml. Before, they created a new pnpm-workspace.yaml in the current package, which made that package the workspace root. Settings stored in .npmrc are still written to the current directory #​13757.

  • pnpm now reads the workspace directory override from PNPM_CONFIG_WORKSPACE_DIR, like other settings. NPM_CONFIG_WORKSPACE_DIR still works as a fallback #​16275.

  • pnpm now fails with ERR_PNPM_AUTH_INVALID_BASE64 when a registry's _password in .npmrc is not valid base64. Before, it sent the value as the raw password. A username or _password left empty, for example by an unset environment variable, now supplies no credential #​16273.

  • proxy=false now turns proxying off even when HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY is set. pnpm no longer sends requests through a proxy named only in ALL_PROXY.

  • pnpm install now runs the install hooks of a config dependency plugin's pnpmfile, including readPackage, afterAllResolved, and custom resolvers. Its pnpmfile is also counted in pnpmfileChecksum. Before, only the plugin's updateConfig hook ran, so a plugin could not change the resolved dependencies.

  • A pnpmfile fetchers hook now runs once per package on a fresh install when it handles a resolution with a custom type or delegates a git-hosted one to the same subdirectory #​15584. These packages were fetched a second time for installation, so the installed files could come from a different archive than the one their dependencies were read from. The hook also no longer runs twice when a resolvers hook returns a tarball resolution without a manifest #​15025.

  • pnpm install now re-fetches a package from a custom resolver when the integrity of its resolution changes, with or without enableGlobalVirtualStore. It used to update the lockfile but keep the old files in node_modules #​15670.

  • pnpm install now rejects invalid results from a readPackage hook. A hook that returns a non-object value fails with ERR_PNPM_BAD_READ_PACKAGE_HOOK_RESULT #​15730. A hook that sets a dependency range to a value other than a string, such as undefined, fails with an error that names the dependency, the package and the pnpmfile. Delete the property to remove a dependency #​15705.

Global packages, pnpm versions, and runtimes
  • pnpm update --global now reinstalls the global packages that pnpm 10 installed into the previous global directory, <global-dir>/5, so their commands are linked into the pnpm home bin directory again and pnpm list --global lists them. Once every package is migrated, pnpm deletes the previous directory and the commands pnpm 10 linked into the pnpm home #​11528.

  • A signal sent to pnpm, such as SIGTERM, now reaches the pnpm that pnpm switches to because of packageManager or devEngines.packageManager, and the one that pnpm with runs. The signal used to be dropped, so scripts running under that pnpm never got to shut down #​9948.

  • On arm64 musl Linux, such as Alpine on ARM, switching to a pinned pnpm older than 12 now runs the JavaScript pnpm package. The standalone executable of those versions crashed at startup on that platform #​10443.

  • Global shims such as node now work when pnpm runs through a relative symlink, as with a Homebrew install. They were copies of that symlink and did not resolve from the global bin directory #​15691.

  • pnpm env remove --global deletes Node.js versions that pnpm installed into its own store, including when another tool installed pnpm #​8357.

  • pnpm self-update no longer suggests a downgrade when minimumReleaseAge holds back the registry's latest release. It now says that release is still within the cutoff #​12006.

Windows
  • Interrupting a script with Ctrl+C on Windows no longer leaves the terminal stuck #​14860. A script that runs through a batch shim, as vite dev does through vite.CMD, made cmd.exe wait forever on its "Terminate batch job (Y/N)?" answer, and every following keystroke went to that prompt. pnpm now ends a cmd.exe script shell once it has sat for a second after the interrupt with nothing running under it. A script that takes longer to shut down is still waited for. A second Ctrl+C ends the script's shell at once.

  • On Windows, pnpm run now passes the arguments after the script name to the script as typed. Before, cmd expanded %VAR% in them and backslashes arrived doubled. Line breaks still arrive as the two characters \n, because cmd cannot pass them. The command line pnpm prints for the script quotes the arguments the same way on every platform #​16257.

  • The Windows pnpm.exe runs on a clean Windows install that does not have the Visual C++ Redistributable. It used to exit immediately on startup because that runtime was missing #​15723.

  • On Windows, the .cmd command shims in node_modules/.bin now keep a % in the project path. Before, cmd.exe expanded it as a variable reference, so the command received a mangled NODE_PATH #​15716. Command shims also run tools whose paths contain non-ASCII characters #​6999, including the PowerShell shims in Windows PowerShell 5.1 #​16217.

  • Bin shims in node_modules/.bin run from Cygwin on Windows again. The shims passed a /cygdrive/c/... path to the Windows node found on PATH, so Node.js failed with Cannot find module 'C:\cygdrive\c\...' #​12845.

  • On Windows, installing pnpm with npm inside a project now writes node_modules/.bin shims that run pnpm.exe. A global install with npm install --location=global now gets the same shims as npm install -g #​15688.

  • pnpm install no longer fails with ERR_PNPM_WORKSPACE_INVALID_GLOB on Windows for a wildcard pattern such as plugins/*/* in pnpm-workspace.yaml when the workspace is on a different drive than the pnpm cache or state directory #​16239.

  • On Windows, pnpm install no longer skips a dependency's build script on a later install when the package ships an executable file and the script changes nothing inside the package directory #​15667.

  • pnpm setup no longer writes the pn.ps1, pnpx.ps1, and pnx.ps1 PowerShell wrappers. It also removes the ones an earlier setup wrote. PowerShell now runs pn, pnpx, and pnx through their .cmd wrappers, like pnpm itself. Before, these aliases failed with a "not digitally signed" error wherever the execution policy blocks unsigned scripts #​8444.

  • pnpm setup on Windows no longer panics when an unrelated environment variable has a name containing a non-ASCII character. It skips that variable #​15684.

  • On Windows, pnpm setup repairs the PNPM_HOME registry type left by older pnpm versions, even when the configured directory has not changed.

  • On Windows, the ERR_PNPM_BAD_ENV_FOUND error of pnpm setup now shows the value PNPM_HOME is currently set to. Before, it showed the directory pnpm wanted to set.

  • On Windows, pnpm expands nested %VAR% references in PNPM_HOME and the other directory environment variables it uses for its home, store, cache, state, and config directories. pnpm fails with an error when a %VAR% reference remains after expansion #​13236.

  • On Windows, if the global bin directory is not in PATH and a PATH entry still contains an unexpanded variable such as %PNPM_HOME%, the error now names that entry. A variable referenced from the user Path must be set to a full path and stored as a plain string (REG_SZ) for the entry to expand #​5283.

Inspecting dependencies
  • pnpm audit and pnpm audit signatures now fail with an error when the lockfile contains unresolvable dependency references #​13638.

  • pnpm licenses list now reports the actual on-disk package locations when using nodeLinker: hoisted or shamefully-hoist: true #​8589. With --json, its paths array now includes every installed copy of a package, including hoisted copies and isolated installations with different peer dependencies.

  • pnpm root now prints the configured modulesDir. It used to print node_modules regardless of the setting. A project's own modulesDir from packageConfigs is printed too #​9113.

Output and messages
  • With the default and append-only reporters, installs with --loglevel warn or --loglevel error now print the full output of a failed install script. The output of successful scripts, including the root project's own install hooks, stays hidden. With --loglevel warn, pnpm also prints ignored build script warnings.

  • When a dependency fails to resolve, the error now shows the cause. For example, a Node.js runtime download behind a proxy that re-signs TLS now reports invalid peer certificate: UnknownIssuer #​9556.

  • When installing a git dependency over SSH fails with Permission denied (publickey), pnpm suggests checking the loaded keys with ssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewrite that leaves the recorded URL alone #​13743.

  • Lockfile verification now fails with ERR_PNPM_TARBALL_URL_MISMATCH, ERR_PNPM_TARBALL_REVISION_MISMATCH, or ERR_PNPM_MISSING_NAMED_REGISTRY when every rejected entry failed that check. These failures were reported as the generic ERR_PNPM_LOCKFILE_RESOLUTION_VERIFICATION.

  • The lockfile verification error now suggests relaxing the policy that flagged an entry only if a fresh resolution still fails and you trust the affected packages. Errors from checks that no policy controls, such as a missing tarball integrity, no longer suggest relaxing a policy #​14411.

  • pnpm install no longer prints an extra Progress: line after the progress line is marked done #​16184.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.7.0

Compare Source

v12.6.0

Compare Source

v12.5.1

Compare Source

v12.5.0

Compare Source

v12.4.2

Compare Source

v12.4.1

Compare Source

v12.4.0

Compare Source

v12.3.4

Compare Source

v12.3.3

Compare Source

v12.3.2

Compare Source

v12.3.1

Compare Source

v12.3.0

Compare Source

v12.2.1

Compare Source

v12.2.0

Compare Source

v12.1.0

Compare Source

v12.0.0

Compare Source

v11.28.5

Compare Source

v11.28.4

Compare Source

v11.28.3

Compare Source

v11.28.2

Compare Source

v11.28.1

Compare Source

v11.28.0

Compare Source

v11.27.1

Compare Source

v11.27.0

Compare Source

v11.26.0

Compare Source

v11.25.0

Compare Source

v11.24.0

Compare Source

v11.23.0

Compare Source

v11.22.0

Compare Source

v11.21.0

Compare Source

v11.20.0

Compare Source

v11.19.0

Compare Source

v11.18.0

Compare Source

v11.17.0

Compare Source

v11.16.0

Compare Source

v11.15.1

Compare Source

v11.15.0

Compare Source

v11.14.0

Compare Source

v11.13.1

Compare Source

v11.13.0

Compare Source

v11.12.0

Compare Source

v11.11.0

Compare Source

v11.10.0

Compare Source

v11.9.0

Compare Source

v11.8.0

Compare Source

v11.7.0

Compare Source

v11.6.0

Compare Source

v11.5.3

Compare Source

v11.5.2

Compare Source

v11.5.1

Compare Source

v11.5.0

Compare Source

v11.4.0

Compare Source

v11.3.0

Compare Source

v11.2.2

Compare Source

v11.2.1

Compare Source

v11.2.0

Compare Source

v11.1.3

Compare Source

v11.1.2

Compare Source

v11.1.1

Compare Source

v11.1.0

Compare Source

v11.0.9

Compare Source

v11.0.8

Compare Source

v11.0.7

Compare Source

v11.0.6

Compare Source

v11.0.5

Compare Source

v11.0.4

Compare Source

v11.0.3

Compare Source

v11.0.2

Compare Source

v11.0.1

Compare Source

v11.0.0

Compare Source

v10.34.6

Compare Source

v10.34.5

Compare Source

v10.34.4

Compare Source

v10.34.3

Compare Source

v10.34.2

Compare Source

v10.34.1

Compare Source

v10.34.0

Compare Source

v10.33.4

Compare Source

v10.33.3

Compare Source

v10.33.2

Compare Source

v10.33.1

Compare Source

v10.33.0

Compare Source

v10.32.1

Compare Source

v10.32.0

Compare Source

v10.31.0

Compare Source

v10.30.3

Compare Source

v10.30.2

Compare Source

v10.30.1

Compare Source

v10.30.0

Compare Source

v10.29.3

Compare Source

v10.29.2

Compare Source

v10.29.1

Compare Source

v10.28.2

Compare Source

v10.28.1

Compare Source

v10.28.0

Compare Source

v10.27.0

Compare Source

v10.26.2

Compare Source

v10.26.1

Compare Source

v10.26.0

Compare Source

v10.25.0

Compare Source

v10.24.0

Compare Source

v10.23.0

Compare Source

v10.22.0

Compare Source

v10.21.0

Compare Source

v10.20.0

Compare Source

v10.19.0

Compare Source

v10.18.3

Compare Source

v10.18.2

Compare Source

v10.18.1

Compare Source


  • If you want to rebase/retry this PR, check this box

This branch had an error being deployed

1 failed deployment
Preview — e454fc59 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants