Sign in

Zoltan Kochan

@kochan.io
2.1K followers 181 following 158 posts

Developer, maker of @pnpm.io Works on dependency management at bit.dev

PostsRepliesMedia
Zoltan Kochan @kochan.io · 17/08/2026
Has anyone moved from Github? what are the alternatives for open source?
120
Zoltan Kochan @kochan.io · 16/08/2026
WTF is your problem?
000
Zoltan Kochan @kochan.io · 01/07/2026
Yeah, I hate working with rust.I had to buy a 4TB ssd. Definitely will look into it
170
Zoltan Kochan @kochan.io · 25/06/2026
it should be fine as long as the users are not paying for access.
020
Zoltan Kochan @kochan.io · 25/06/2026
We can revise the license later to what makes most sense. I wanted to start with a stricter license. IMO the current license already makes it very useful.
010
Zoltan Kochan @kochan.io · 25/06/2026
or do you mean hosting your own packages public packages from your own registry? that might be ok.
000
Zoltan Kochan @kochan.io · 25/06/2026
> are private installs always free or could a future private product by you cause a noncompete violation? I am not sure I follow. Self-hosting is allowed. Are you asking if the license would change in the future? It could, although I am not sure it would make sense for us to disallow self-hosting.
000
Zoltan Kochan @kochan.io · 25/06/2026
We will offer a service. > Would offering one for free also be considered competing? Of course it would.
200
Zoltan Kochan @kochan.io · 24/06/2026
We don't want a 3rd party to make a business from selling our registry as a service. You can host the registry for free for your own needs. You can't sell it as a service.
090
Zoltan Kochan @kochan.io · 13/06/2026
I am not sure what you mean
120
Zoltan Kochan @kochan.io · 07/06/2026
I have some early benchmark results with my custom @pnpm.io registry. In different scenarios, overall install times are 2 to 7 times faster than even the already very fast pnpm in Rust. Looks promising.
2636
Zoltan Kochan @kochan.io · 26/05/2026
Check this out
3503
Reposted by Zoltan Kochan
PodRocket Podcast @podrocket.bsky.social · 19/05/2026
pnpm lead maintainer @kochan.io joined PodRocket to talk about pnpm 11: the 24-hour install rule, the new allow-builds config, the global virtual store, and what's coming in v12... including the highly anticipated Rust rewrite. YT: buff.ly/sUJL3H3 Apple: buff.ly/MIifAvK Spotify: buff.ly/heggcl9
041
Zoltan Kochan @kochan.io · 18/05/2026
I do have an idea how to make this work seamlessly but it won't be in priority for a bit.
010
Zoltan Kochan @kochan.io · 04/05/2026
Great!
010
Zoltan Kochan @kochan.io · 10/04/2026
Yeah, for editing I would probably recommend temporarily disabling the GVS. But if you need to edit node_modules frequently, you probably need to have a better workflow.
020
Zoltan Kochan @kochan.io · 10/04/2026
Watching the lockfile would suffice
120
Zoltan Kochan @kochan.io · 10/04/2026
right, I believe the symlinked node_modules layout is already broken with the ts file watcher in vscode. For some reason it watches hundreds of more files than with a hoisted node_modules. I couldn't figure out the reason.
210
Zoltan Kochan @kochan.io · 10/04/2026
Don't file watchers ignore files in node_modules? In my setup it works without issues. I am using this by default on my machine since summer 2025. Though I mainly use neovim for development.
120
Zoltan Kochan @kochan.io · 10/04/2026
"CAS: stores every package once, by content hash" - this is not correct. It stores every file from every package once by content hash. Not the package itself.
110
Zoltan Kochan @kochan.io · 10/04/2026
Sounds correct
120
Zoltan Kochan @kochan.io · 10/04/2026
Without the global virtual store you need to create thousands of hardlinks and hunders of symlinks. With the GVS in most cases pnpm will just create a few symlinks to node_modules layouts already present in this central location. pnpm.io/11.x/global-...
pnpm.io
180
Zoltan Kochan @kochan.io · 10/04/2026
We did 19666 steps🤯
140
Zoltan Kochan @kochan.io · 25/03/2026
Just run install to resolve conflicts
111
Zoltan Kochan @kochan.io · 13/03/2026
That is just a helper script that i created for usage in the pnpm repository. I don’t know if it makes sense to integrate something like that into pnpm.
020
Reposted by Zoltan Kochan
pnpm @pnpm.io · 13/03/2026
pnpm + Git Worktrees for Multi-Agent Development pnpm.io/11.x/git-wor...
pnpm.io
pnpm + Git Worktrees for Multi-Agent Development | pnpm
When multiple AI agents need to work on the same monorepo simultaneously, they each need an isolated working copy with fully functional nodemodules. Git worktrees combined with pnpm's global virtual s...
1398
Zoltan Kochan @kochan.io · 21/02/2026
I just review less. PRs are waiting for weeks sometimes.
000
Zoltan Kochan @kochan.io · 13/02/2026
pnpm fails on unknown flags. And known flags won't be installed as packages. Maybe there is some edge case where you can escape the dashes. I have never tested it.
020
Zoltan Kochan @kochan.io · 05/02/2026
It is also available as an opt-in feature in v10: pnpm.io/settings#blo...
pnpm.io
Settings (pnpm-workspace.yaml) | pnpm
pnpm gets its configuration from the command line, environment variables, pnpm-workspace.yaml, and
020
Zoltan Kochan @kochan.io · 05/02/2026
Additionally, pnpm 11 will block dependencies from exotic sources (like Git) in subdependencies.
2213
Zoltan Kochan @kochan.io · 16/12/2025
Vox is running out of ideas.
020
Reposted by Zoltan Kochan
Party Like It’s 1939 @symfonikz.blacksky.app · 16/12/2025
Therein lies the rub: AI cannot have “ideas” of its own. Every “idea” you thought AI had came from a person, either through prompting or theft. The way to jumpstart the “idea machine” is to have people focused less on survival and more on living passionately.
42218
Reposted by Zoltan Kochan
pnpm @pnpm.io · 08/12/2025
The Seattle Times is piloting pnpm’s client-side defenses—blocked lifecycle scripts, release cooldowns, and trust policy—to stop worms like Shai-Hulud 2.0 before they land. Read their story: pnpm.io/blog/2025/12...
pnpm.io
How We're Protecting Our Newsroom from npm Supply Chain Attacks | pnpm
We got lucky with Shai-Hulud 2.0.
1163
Zoltan Kochan @kochan.io · 04/12/2025
That whole output is from codemod
000
Zoltan Kochan @kochan.io · 04/12/2025
I guess codemod is a package manager of itself and they have switched to some new types of codemods. That is why it prints legacy
100
Zoltan Kochan @kochan.io · 03/12/2025
Pnpx is not deprecated. I don’t know why there’s a warning from the codemod
210
Reposted by Zoltan Kochan
Piotrek Koszuliński @pkoszulinski.bsky.social · 24/11/2025
Yet another reminder to use @pnpm.io's minimum dependency age. pnpm.io/settings#min...
1124
Zoltan Kochan @kochan.io · 12/11/2025
I somewhat agree with your points. However, this feature was the most upvoted in our repository. The npm registry has advertised provenance as the solution to the supply chain problems.
120
Zoltan Kochan @kochan.io · 11/11/2025
Yeah, but i think almost no packages use provenance at the moment at all
100
Zoltan Kochan @kochan.io · 11/11/2025
Yes, it will be possible to do both by name and version(s)
120
Zoltan Kochan @kochan.io · 11/11/2025
There will be a setting to exclude packages from the rule. Although some believe it is a bad idea. Someone suggested to even ship a list of exceptions.
110
Zoltan Kochan @kochan.io · 11/11/2025
Yes, that’s the only safe way of doing it. We’re not fixing it only for the lockfile update case
210
Zoltan Kochan @kochan.io · 11/11/2025
I am not sure there’s a better way to do it.
110
Reposted by Zoltan Kochan
pnpm @pnpm.io · 10/11/2025
🚀 pnpm v10.21 is out! This release introduces two powerful new security & compatibility features: 1️⃣ Automatic Node.js runtime installation for dependencies 2️⃣ Configurable trust policy for detecting supply-chain downgrades 🧵👇
1589
Zoltan Kochan @kochan.io · 10/11/2025
Sometimes I can’t tell if someone was using an agent or not but reviewing pull requests takes a lot of my time. I probably spend double the time on the review if they use agents.
360
Reposted by Zoltan Kochan
ECMAScript.News @ecmascript.news · 10/11/2025
pnpm 10.21: installing Node.js runtimes for dependencies, not installing dependencies with decreased trust levels, and more @kochan.io @pnpm.io pnpm.io/blog/release... #ECMAScript #JavaScript
pnpm.io
pnpm 10.21 | pnpm
Added support for Node.js runtime installation for dependencies and a setting for configuring trust policy.
073
Zoltan Kochan @kochan.io · 27/09/2025
I am not making any promises about the libraries. The major version is the major version of pnpm cli x100. So a library can have up to 99 breaking changes till the next pnpm cli comes out
130
Reposted by Zoltan Kochan
Software Engineering Daily @softwaredaily.bsky.social · 18/09/2025
Zoltan Kochan is a full stack web developer and the creator of @pnpm.io. He joins the show with @joshuakgoldberg.com to talk about the state of package management for web dev. @kochan.io softwareengineeringdaily.com/2025/09/18/p...
softwareengineeringdaily.com
pnpm with Zoltan Kochan - Software Engineering Daily
Traditional package management systems for JavaScript have faced several inefficiencies related to dependency storage, resolution, and project performance. pnpm is a fast, disk-efficient package manag...
1205
Reposted by Zoltan Kochan
Socket @socket.dev · 15/09/2025
After recent npm supply chain attacks, @pnpm.io 10.16 adds a setting for delayed dependency updates. Tools like Taze and npm-check-updates are testing similar “maturity” options, hinting at a cautious new trend in #JavaScript package management. socket.dev/blog/pnpm-10... #NodeJS
socket.dev
pnpm 10.16 Adds New Setting for Delayed Dependency Updates -...
pnpm's new minimumReleaseAge setting delays package updates to prevent supply chain attacks, with other tools like Taze and NCU following suit.
0188