chore(deps): update pnpm to v12 - #710
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 11, 2026 20:42
b512165 to
979057d
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 16, 2026 11:03
979057d to
6ffd97d
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 20, 2026 05:59
6ffd97d to
bd5d686
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 24, 2026 01:50
bd5d686 to
ccdb6c0
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
September 29, 2026 18:34
ccdb6c0 to
dcba3d3
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
October 4, 2026 01:38
dcba3d3 to
0416df9
Compare
renovate
Bot
force-pushed
the
renovate/pnpm-12.x
branch
from
October 5, 2026 00:49
0416df9 to
e454fc5
Compare
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
10.18.0→12.9.1Release Notes
pnpm/pnpm (pnpm)
v12.9.1: pnpm 12.9.1Compare Source
This release moves the WebContainer build into a separate
@pnpm/wasmpackage, shrinks thepnpmpackage back to about 4 MB, and fixespnpm publishwith provenance from GitLab CI.Patch Changes
The WebAssembly build for StackBlitz WebContainers now ships as a separate
@pnpm/wasmpackage. Thepnpmand@pnpm/exepackages no longer include it, which brings their unpacked size back from about 55 MB to about 4 MB. In a WebContainer, install@pnpm/wasmwith npm to get thepnpmcommand.pnpm publishwith provenance from GitLab CI is no longer rejected by the npm registry with a 422 error. The provenance statement now includes the GitLab CI variables ininvocation.parameters, as npm does #16551.pnpm audit signaturesnow uses the TLS settings of the redirect target when a registry redirects its signing-keys request, for example to registry.npmjs.org. Acafilescoped to a private registry no longer makes the redirected request fail #16541.Fixed
pnpm install --frozen-lockfilerejecting an up-to-date lockfile when an injected workspace package uses a catalog entry inpeerDependencies#16557.The
[<since>]filter selector works again with Git 2.24 through 2.27 #16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.It also detects changes in projects whose directory names contain non-ASCII characters. Such a change used to be credited to the parent project.
changedFilesIgnorePatternandtestPatternnow match changed files whose names contain non-ASCII characters.The
pnpmexecutable is about 10% smaller. On macOS arm64 it went from 45.1 MB to 40.3 MB.Sped up trust downgrade checks for packages with long release histories.
With
optimisticRepeatInstall: false,pnpm installnow runs the projects' own lifecycle scripts, such asprepare, even whennode_modulesis already up to date #16545.pnpm self-updatenow fails for Homebrew-installed pnpm and prints thebrew upgradecommand for the installed formula, such asbrew upgrade pnpmorbrew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #16547.Platinum Sponsors
Gold Sponsors
v12.9.0: pnpm 12.9Compare Source
This release runs pnpm in StackBlitz WebContainers, adds a per-registry
networkConcurrencysetting, and records every installed project in the store. It also carries a security fix forpnpm login.Minor Changes
pnpm now automatically uses WebAssembly in StackBlitz WebContainers, including when installation scripts are disabled. Native installations continue to use the native executable when installation scripts are enabled.
A
registriesentry can now setnetworkConcurrency, the most requests pnpm keeps in flight to that registry's origin. Requests to other registries keep the overall limit. The setting may live inpnpm-workspace.yamlor the globalconfig.yaml.pnpm installnow records every project it installs in the store'sprojectsdirectory, as a symlink to the project directory. A--frozen-storeinstall without the global virtual store still records nothing. Only projects that used the global virtual store were recorded before #6929.Patch Changes
pnpm loginno longer forwards credentials in its request body to another origin during redirects.Installing packages
Fixed
pnpm installfailing on Android withERR_PNPM_STORE_DIR_ACQUIRE_OPERATION_LOCK#16508.pnpm install --frozen-lockfileagain succeeds when a workspace project recorded inpnpm-lock.yamlhas no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without apackage.json#16453.pnpm install --frozen-lockfileno longer requires apnpm-lock.yamlin a project that has no dependencies. It also succeeds whenpnpm-lock.yamlrecords only the pinned pnpm version, as other commands write it when they run before the first install #16477.Fixed
pnpm install --frozen-lockfilerejecting a fresh lockfile when an injected workspace dependency has an optional peer supplied by another workspace project #16428.With
nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put innode_modules. This also covers the install thatpnpm --filter <selector> runandpnpm --filter <selector> execstart before the command. Before, these installs removed every package that only the unselected projects needed #16483.pnpm installwithnodeLinker: hoistednow refreshes directories supplied by custom fetchers when reinstalling. pnpm also keeps the symlinks inside those directories.With
enableGlobalVirtualStoreon, scripts can run entry points that a CommonJS require hook loads again, such asts-node index.ts. They failed withERR_UNKNOWN_FILE_EXTENSIONon Node.js versions without built-in TypeScript support #16436.pnpm now keeps each project's current lockfile and hidden hoisted dependencies in its own
node_modules/.pnpmwhenvirtualStoreDirpoints at a shared global virtual store.--virtual-store-dirnow sets the global virtual store's location too pnpm/tasks#47.pnpm cleanno longer deletes the project whenvirtualStoreDirorglobalVirtualStoreDiris set to the project directory. It also leaves a directory outside the project alone when the setting reaches it through a symlink. It now removes a global virtual store thatglobalVirtualStoreDirplaces inside the project, as it does forvirtualStoreDir.Optional dependencies
pnpm installno longer fails when a dependency of an optional dependency is missing from the registry. Like npm, pnpm now leaves out the nearest optional dependency above it, together with its subtree #16511.When an optional dependency fails to build, pnpm now removes its link from
node_modules. A repeatpnpm installthen reports "Already up to date" and no longer reruns the failing build #16468.pnpm installnow prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer counted in thePackages: +Nsummary. Thepnpm:skipped-optional-dependencylog reports the skip with thefetch_failurereason #16514.Resolving dependencies
Fixed
pnpm installchanging an unchanged project's direct dependency to a sibling workspace's pinned version when its dependency tree contains a cycle #16417.With
autoDedupeenabled, downgrading a dependency in one workspace project now moves the other projects to that version when it satisfies their ranges. This also applies to a filteredpnpm --filter <project> add#16432.pnpm installandpnpm dedupenow move an optional peer to the version already in the dependency graph when no other package provides its locked version anymore. After a bump such asvue3.5.40 to 3.5.43, the lockfile kept a second copy of@vue/server-rendererfor@vue/test-utils#16443.pnpm dedupe --checkno longer fails right afterpnpm installwhen a project's optional peer is satisfied by a package another workspace project installs.pnpm dedupenow picks the same versions for that package's dependencies aspnpm install#16447.pnpm installno longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #16418.With
autoDedupeenabled,pnpm install --lockfile-onlyno longer resolves the dependency graph again when nothing changed since an earlier--lockfile-onlyinstall deduplicated the lockfile. Such an install keeps the lockfile even if versions were published since it was written, or if only a setting such asresolutionModechanged. Runpnpm dedupeto apply such a change #16458.Speed and network
A repeat
pnpm installin a large workspace reports "Already up to date" faster #16487.Sped up dependency resolution of workspaces with many peer dependencies.
pnpm installsends fewer registry metadata requests when the lockfile already decides which version a range resolves to. This now also covers ranges that several locked versions satisfy when one of them outranks the others, and direct dependencies kept at their locked version. Packages thatminimumReleaseAgeExcludelists without a version now reuse cached registry metadata the same way they do whenminimumReleaseAgeis not set #16458.pnpm no longer downloads every packument again on each install from a registry whose metadata responses forbid caching, such as
Cache-Control: no-store. pnpm revalidates the cached metadata with a conditional request, so a registry that supports conditional requests answers with a 304 when the package has not changed #16528.Cached metadata for a package published within
minimumReleaseAgeis now revalidated with its ETag, so the npm registry can answer304 Not Modified. Before, the next install that checked the cache downloaded the whole document again #16506.A fetch timeout while other downloads from the same host are still running now lowers concurrency for that host to one connection. Retries of that request, and later downloads from that host, use the lower concurrency. Other hosts keep the configured concurrency #12791.
Sped up
pnpm install --offlinewhen the version a range picks is not in the store. While it looks for a version the store holds, pnpm now reads only the versions the range admits #16495.pnpm install --offlinenow reuses config dependency tarballs that are already present in the store pnpm/tasks#46.Running scripts
pnpm -s <script>runs the script again, with-smeaning--sequentialas it does forpnpm run -s <script>. pnpm rejected it with "unexpected argument '-s' found" #16446.pnpm runandpnpm execnow warn and run the command when the install thatverifyDepsBeforeRunstarts fails. This lets scripts run in sandboxes where pnpm cannot install, such as containers with a read-only store or no network #15173.A filtered
pnpm runorpnpm execnow finds dependencies out of date when a workspace dependency of a selected project has nonode_modulesdirectory, as after a filtered install. WithverifyDepsBeforeRun: install, pnpm installs that dependency before running the command pnpm/tasks#45.Scripts run without a terminal no longer start a second
sheach. One watchdog per pnpm command now ends every script's process group if pnpm is killed, sopnpm -r runacross many projects starts half as many processes #16489.Terminate batch job (Y/N)?no longer appears after pressing Ctrl+C in a script started withpnpmfrom PowerShell or cmd on Windows #16502.pnpm rebuildandpnpm approve-buildsrefresh command launchers when a build changes a command's interpreter or replaces it with a native executable. Dependent packages' build scripts use the refreshed launchers.When
pnpm run <script>orpnpm <script>finds nothing to run and--filterfollows the script name, the error now suggests putting the filter option before the script name #4655.Package-name filters now support
?to match one character #2817.The pinned pnpm and
pnpm self-updatepnpm no longer downloads the project's pinned pnpm version again on every command when
nodeVersioninpnpm-workspace.yamlnames a different Node.js major than thenodeonPATH. Before, each of those commands took about a second longer and failed without network access #16497.Several
pnpmcommands started at once in a project that pinspackageManagerno longer fail withThe process cannot access the file because it is being used by another processon Windows while the pinned pnpm is being installed.pnpm can now switch to a
packageManagerversion below 11 on x64 musl Linux, such as Alpine #16467.A
devEngines.packageManagerrange no longer makes pnpm replace the version recorded inpnpm-lock.yamlwith the running pnpm while the recorded version still satisfies the range. When pnpm does record a version, it records the running pnpm only if it meets `minimumReleaseAgConfiguration and pnpmfile hooks
Every setting pnpm supports can now be set with
--config.<name>=<value>on the command line, not only the ones whose command also carries a matching flag. Before,pnpm install --config.frozen-lockfile=truedropped the setting and rewrotepnpm-lock.yamlas though the install had not been frozen #16276.Settings given on the command line, such as
--registryand--store-dir, now take precedence over the values a pnpmfileupdateConfighook sets #14063.pnpm config set --location=projectandpnpm config delete --location=project, run from a package inside a workspace, now write settings that belong inpnpm-workspace.yamlto the workspace root'spnpm-workspace.yaml. Before, they created a newpnpm-workspace.yamlin the current package, which made that package the workspace root. Settings stored in.npmrcare still written to the current directory #13757.pnpm now reads the workspace directory override from
PNPM_CONFIG_WORKSPACE_DIR, like other settings.NPM_CONFIG_WORKSPACE_DIRstill works as a fallback #16275.pnpm now fails with
ERR_PNPM_AUTH_INVALID_BASE64when a registry's_passwordin.npmrcis not valid base64. Before, it sent the value as the raw password. Ausernameor_passwordleft empty, for example by an unset environment variable, now supplies no credential #16273.proxy=falsenow turns proxying off even whenHTTP_PROXY,HTTPS_PROXY, orALL_PROXYis set. pnpm no longer sends requests through a proxy named only inALL_PROXY.pnpm installnow runs the install hooks of a config dependency plugin's pnpmfile, includingreadPackage,afterAllResolved, and custom resolvers. Its pnpmfile is also counted inpnpmfileChecksum. Before, only the plugin'supdateConfighook ran, so a plugin could not change the resolved dependencies.A pnpmfile
fetchershook now runs once per package on a fresh install when it handles a resolution with a customtypeor delegates a git-hosted one to the same subdirectory #15584. These packages were fetched a second time for installation, so the installed files could come from a different archive than the one their dependencies were read from. The hook also no longer runs twice when aresolvershook returns a tarball resolution without a manifest #15025.pnpm installnow re-fetches a package from a custom resolver when theintegrityof its resolution changes, with or withoutenableGlobalVirtualStore. It used to update the lockfile but keep the old files innode_modules#15670.pnpm installnow rejects invalid results from areadPackagehook. A hook that returns a non-object value fails withERR_PNPM_BAD_READ_PACKAGE_HOOK_RESULT#15730. A hook that sets a dependency range to a value other than a string, such asundefined, fails with an error that names the dependency, the package and the pnpmfile. Delete the property to remove a dependency #15705.Global packages, pnpm versions, and runtimes
pnpm update --globalnow reinstalls the global packages that pnpm 10 installed into the previous global directory,<global-dir>/5, so their commands are linked into the pnpm homebindirectory again andpnpm list --globallists them. Once every package is migrated, pnpm deletes the previous directory and the commands pnpm 10 linked into the pnpm home #11528.A signal sent to pnpm, such as
SIGTERM, now reaches the pnpm that pnpm switches to because ofpackageManagerordevEngines.packageManager, and the one thatpnpm withruns. The signal used to be dropped, so scripts running under that pnpm never got to shut down #9948.On arm64 musl Linux, such as Alpine on ARM, switching to a pinned pnpm older than 12 now runs the JavaScript
pnpmpackage. The standalone executable of those versions crashed at startup on that platform #10443.Global shims such as
nodenow work when pnpm runs through a relative symlink, as with a Homebrew install. They were copies of that symlink and did not resolve from the global bin directory #15691.pnpm env remove --globaldeletes Node.js versions that pnpm installed into its own store, including when another tool installed pnpm #8357.pnpm self-updateno longer suggests a downgrade whenminimumReleaseAgeholds back the registry'slatestrelease. It now says that release is still within the cutoff #12006.Windows
Interrupting a script with Ctrl+C on Windows no longer leaves the terminal stuck #14860. A script that runs through a batch shim, as
vite devdoes throughvite.CMD, made cmd.exe wait forever on its "Terminate batch job (Y/N)?" answer, and every following keystroke went to that prompt. pnpm now ends a cmd.exe script shell once it has sat for a second after the interrupt with nothing running under it. A script that takes longer to shut down is still waited for. A second Ctrl+C ends the script's shell at once.On Windows,
pnpm runnow passes the arguments after the script name to the script as typed. Before,cmdexpanded%VAR%in them and backslashes arrived doubled. Line breaks still arrive as the two characters\n, becausecmdcannot pass them. The command line pnpm prints for the script quotes the arguments the same way on every platform #16257.The Windows
pnpm.exeruns on a clean Windows install that does not have the Visual C++ Redistributable. It used to exit immediately on startup because that runtime was missing #15723.On Windows, the
.cmdcommand shims innode_modules/.binnow keep a%in the project path. Before, cmd.exe expanded it as a variable reference, so the command received a mangledNODE_PATH#15716. Command shims also run tools whose paths contain non-ASCII characters #6999, including the PowerShell shims in Windows PowerShell 5.1 #16217.Bin shims in
node_modules/.binrun from Cygwin on Windows again. The shims passed a/cygdrive/c/...path to the Windowsnodefound onPATH, so Node.js failed withCannot find module 'C:\cygdrive\c\...'#12845.On Windows, installing pnpm with npm inside a project now writes
node_modules/.binshims that runpnpm.exe. A global install withnpm install --location=globalnow gets the same shims asnpm install -g#15688.pnpm installno longer fails withERR_PNPM_WORKSPACE_INVALID_GLOBon Windows for a wildcard pattern such asplugins/*/*inpnpm-workspace.yamlwhen the workspace is on a different drive than the pnpm cache or state directory #16239.On Windows,
pnpm installno longer skips a dependency's build script on a later install when the package ships an executable file and the script changes nothing inside the package directory #15667.pnpm setupno longer writes thepn.ps1,pnpx.ps1, andpnx.ps1PowerShell wrappers. It also removes the ones an earlier setup wrote. PowerShell now runspn,pnpx, andpnxthrough their.cmdwrappers, likepnpmitself. Before, these aliases failed with a "not digitally signed" error wherever the execution policy blocks unsigned scripts #8444.pnpm setupon Windows no longer panics when an unrelated environment variable has a name containing a non-ASCII character. It skips that variable #15684.On Windows,
pnpm setuprepairs thePNPM_HOMEregistry type left by older pnpm versions, even when the configured directory has not changed.On Windows, the
ERR_PNPM_BAD_ENV_FOUNDerror ofpnpm setupnow shows the valuePNPM_HOMEis currently set to. Before, it showed the directory pnpm wanted to set.On Windows, pnpm expands nested
%VAR%references inPNPM_HOMEand the other directory environment variables it uses for its home, store, cache, state, and config directories. pnpm fails with an error when a%VAR%reference remains after expansion #13236.On Windows, if the global bin directory is not in
PATHand aPATHentry still contains an unexpanded variable such as%PNPM_HOME%, the error now names that entry. A variable referenced from the userPathmust be set to a full path and stored as a plain string (REG_SZ) for the entry to expand #5283.Inspecting dependencies
pnpm auditandpnpm audit signaturesnow fail with an error when the lockfile contains unresolvable dependency references #13638.pnpm licenses listnow reports the actual on-disk package locations when usingnodeLinker: hoistedorshamefully-hoist: true#8589. With--json, itspathsarray now includes every installed copy of a package, including hoisted copies and isolated installations with different peer dependencies.pnpm rootnow prints the configuredmodulesDir. It used to printnode_modulesregardless of the setting. A project's ownmodulesDirfrompackageConfigsis printed too #9113.Output and messages
With the default and append-only reporters, installs with
--loglevel warnor--loglevel errornow print the full output of a failed install script. The output of successful scripts, including the root project's own install hooks, stays hidden. With--loglevel warn, pnpm also prints ignored build script warnings.When a dependency fails to resolve, the error now shows the cause. For example, a Node.js runtime download behind a proxy that re-signs TLS now reports
invalid peer certificate: UnknownIssuer#9556.When installing a git dependency over SSH fails with
Permission denied (publickey), pnpm suggests checking the loaded keys withssh-add -l. Resolving an SSH URL that refuses the key also shows a local HTTPS rewrite that leaves the recorded URL alone #13743.Lockfile verification now fails with
ERR_PNPM_TARBALL_URL_MISMATCH,ERR_PNPM_TARBALL_REVISION_MISMATCH, orERR_PNPM_MISSING_NAMED_REGISTRYwhen every rejected entry failed that check. These failures were reported as the genericERR_PNPM_LOCKFILE_RESOLUTION_VERIFICATION.The lockfile verification error now suggests relaxing the policy that flagged an entry only if a fresh resolution still fails and you trust the affected packages. Errors from checks that no policy controls, such as a missing tarball integrity, no longer suggest relaxing a policy #14411.
pnpm installno longer prints an extraProgress:line after the progress line is markeddone#16184.Platinum Sponsors
Gold Sponsors
v12.7.0Compare Source
v12.6.0Compare Source
v12.5.1Compare Source
v12.5.0Compare Source
v12.4.2Compare Source
v12.4.1Compare Source
v12.4.0Compare Source
v12.3.4Compare Source
v12.3.3Compare Source
v12.3.2Compare Source
v12.3.1Compare Source
v12.3.0Compare Source
v12.2.1Compare Source
v12.2.0Compare Source
v12.1.0Compare Source
v12.0.0Compare Source
v11.28.4Compare Source
v11.28.3Compare Source
v11.28.2Compare Source
v11.28.1Compare Source
v11.28.0Compare Source
v11.27.1Compare Source
v11.27.0Compare Source
v11.26.0Compare Source
v11.25.0Compare Source
v11.24.0Compare Source
v11.23.0Compare Source
v11.22.0Compare Source
v11.21.0Compare Source
v11.20.0Compare Source
v11.19.0Compare Source
v11.18.0Compare Source
v11.17.0Compare Source
v11.16.0Compare Source
v11.15.1Compare Source
v11.15.0Compare Source
v11.14.0Compare Source
v11.13.1Compare Source
v11.13.0Compare Source
v11.12.0Compare Source
v11.11.0Compare Source
v11.10.0Compare Source
v11.9.0Compare Source
v11.8.0Compare Source
v11.7.0Compare Source
v11.6.0Compare Source
v11.5.3Compare Source
v11.5.2Compare Source
v11.5.1Compare Source
v11.5.0Compare Source
v11.4.0Compare Source
v11.3.0Compare Source
v11.2.2Compare Source
v11.2.1Compare Source
v11.2.0Compare Source
v11.1.3Compare Source
v11.1.2Compare Source
v11.1.1Compare Source
v11.1.0Compare Source
v11.0.9Compare Source
v11.0.8Compare Source
v11.0.7Compare Source
v11.0.6Compare Source
v11.0.5Compare Source
v11.0.4Compare Source
v11.0.3Compare Source
v11.0.2Compare Source
v11.0.1Compare Source
v11.0.0Compare Source
v10.34.6Compare Source
v10.34.5Compare Source
v10.34.4Compare Source
v10.34.3Compare Source
v10.34.2Compare Source
v10.34.1Compare Source
v10.34.0Compare Source
v10.33.4Compare Source
v10.33.3Compare Source
v10.33.2Compare Source
v10.33.1Compare Source
v10.33.0Compare Source
v10.32.1Compare Source
v10.32.0Compare Source
v10.31.0Compare Source
v10.30.3Compare Source
v10.30.2Compare Source
v10.30.1Compare Source
v10.30.0Compare Source
v10.29.3Compare Source
v10.29.2Compare Source
v10.29.1Compare Source
v10.28.2Compare Source
v10.28.1Compare Source
v10.28.0Compare Source
v10.27.0Compare Source
v10.26.2Compare Source
v10.26.1Compare Source
v10.26.0Compare Source
v10.25.0Compare Source
v10.24.0Compare Source
v10.23.0Compare Source
v10.22.0Compare Source
v10.21.0Compare Source
v10.20.0Compare Source
v10.19.0Compare Source
v10.18.3Compare Source
v10.18.2Compare Source
v10.18.1Compare Source