Sign in

pnpm

@pnpm.io
3.5K followers 24 following 108 posts

Fast, disk space efficient package manager pnpm.io

PostsRepliesMedia
Reposted by pnpm
Nx @nx.dev · 23/09/2026
You can add Nx to an existing pnpm workspace without restructuring anything. Install nx at the root, add a small nx.json with your targetDefaults, and run tasks across every project with nx run-many. Caching and task ordering come from there.
052
Reposted by pnpm
RustTrending @rusttrending.bsky.social · 23/09/2026
pnpm: Fast, disk space efficient package manager ★36616 github.com/pnpm/pnpm
github.com
pnpm / pnpm
Fast, disk space efficient package manager
051
pnpm @pnpm.io · 24/09/2026
You might love pnpm after all
030
Reposted by pnpm
Ingvar Stepanyan @rreverser.com · 24/09/2026
Hah yeah moved to pnpm years ago and never looked back. Native builds in pnpm 12 are even more promising.
011
Reposted by pnpm
Anthony Whitford @anthonywhitford.com · 07/09/2026
Upgrading @pnpm.io 11.25.0 -> 12.3.4 resulted in a 38.26% increase in speed/throughput for my CI builds. 🚀 #BuildInPublic
1181
pnpm @pnpm.io · 04/09/2026
For easier migration. The new action is much better.
010
pnpm @pnpm.io · 04/09/2026
why? there is a new action: github.com/pnpm/setup
github.com
GitHub - pnpm/setup: Install pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in one GitHub actions step
Install pnpm and a JavaScript runtime (Node.js, Bun, or Deno) in one GitHub actions step - pnpm/setup
120
pnpm @pnpm.io · 04/09/2026
We plan to make pnpm v12.3.4 the latest version! Due to our minimum release age policy we need to wait at least for 24 hours😭
1211
pnpm @pnpm.io · 12/08/2026
If you have devEngines.packageManager in package.json the generated lockfile is not working with dependabot
020
pnpm @pnpm.io · 11/08/2026
Dependabot still doesn't support pnpm v11. Upvote this issue please: github.com/dependabot/d...
github.com
Support PNPM v11 · Issue #14794 · dependabot/dependabot-core
Is there an existing issue for this? I have searched the existing issues Feature description PNPM vesrion 11 is in release candidate stage, and I would like to use it in my project. However, I see ...
2293
pnpm @pnpm.io · 23/07/2026
Yes, we’ll probably add some github actions for this
000
pnpm @pnpm.io · 21/07/2026
I have answered in the issue. Just use pnpm publish directly. Keep using changesets for the rest.
010
pnpm @pnpm.io · 21/07/2026
Yes, also we’ll have an official github action that you can use to replace renovate and dependabot
010
pnpm @pnpm.io · 21/07/2026
If you are using changesets for versioning, you can now use pnpm CLI directly for version management: pnpm.io/versioning
pnpm.io
Release management | pnpm
Added in: v11.13.0
3442
pnpm @pnpm.io · 21/07/2026
pnpm is supporting changesets now out of the box: pnpm.io/versioning .
x.com
pnpm (@pnpmjs) on X
If you are using changesets for versioning, you can now use pnpm CLI directly for version management: https://t.co/vjVUnvw8mP
120
pnpm @pnpm.io · 15/07/2026
The installation methods of pnpm itself might break. Corepack can’t install it yet
030
pnpm @pnpm.io · 15/07/2026
All workflows in the pnpm monorepo itself are now using pnpm v12.0.0-alpha.12, which is the Rust rewrite of pnpm v11. No breaking changes in the API vs v11.
1381
pnpm @pnpm.io · 10/07/2026
If you are on the latest pnpm v11.10.0 (or v10.34.5), you can try out the pnpm v12 alpha via: pnpm self-update 12.0.0-alpha.5 It is fully in Rust! 🦀
3688
pnpm @pnpm.io · 26/06/2026
It is faster because it can do server side resolution. During resolution your client makes one request to the registry to get the lockfile instead of making thousands of requests for every package’s document.
030
pnpm @pnpm.io · 24/06/2026
Very early sneak peek to pnpr - the pnpm registry: pnpm.io/pnpr/
pnpm.io
Introduction | pnpm
pnpr is a pnpm-compatible npm registry server, written in Rust. It speaks the
410515
pnpm @pnpm.io · 20/06/2026
We are open to suggestions. This was the fastest solution
220
pnpm @pnpm.io · 17/06/2026
That would give attackers time to use the vulnerability pnpm.io/blog/2026/06...
pnpm.io
Why pnpm no longer expands environment variables in a repository's .npmrc | pnpm
pnpm used to expand $ placeholders everywhere it found them — including in the .npmrc and pnpm-workspace.yaml files that live inside the repository you just cloned. That turned out to be a way for a m...
131
Reposted by pnpm
Zoltan Kochan @kochan.io · 07/06/2026
I have some early benchmark results with my custom @pnpm.io registry. In different scenarios, overall install times are 2 to 7 times faster than even the already very fast pnpm in Rust. Looks promising.
2636
Reposted by pnpm
Zoltan Kochan @kochan.io · 26/05/2026
Check this out
3503
pnpm @pnpm.io · 25/05/2026
yes
0100
pnpm @pnpm.io · 25/05/2026
The pnpm e2e tests now use a "pnpm registry" instead of verdaccio. In the future we'll make pnpm faster with this registry.
1642
pnpm @pnpm.io · 19/05/2026
In the next version of pnpm you'll be able to run the Rust engine for fetching, importing, and linking packages.
410711
Reposted by pnpm
Samuel @samuel.fm · 18/05/2026
🫡 thank you regardless, we just switched the bluesky app to pnpm and it’s like a breath of fresh air after being stuck on yarn 1 so long
3101
pnpm @pnpm.io · 18/05/2026
🙌
020
pnpm @pnpm.io · 18/05/2026
not at the moment
120
pnpm @pnpm.io · 18/05/2026
no, but all these additional checks make install slower. Hence I am not sure we will do anything non-security related by default. This is more like a correctness check.
130
pnpm @pnpm.io · 18/05/2026
Yes, just update to pnpm 11.1.3 and you should be fine.
140
Reposted by pnpm
knut @knut.fyi · 12/05/2026
in times like these, I'm very happy that @sanity.io put some of our @opensourcepledge.com dollars on the good folks at @pnpm.io 🫡 (and we made it our mandated package manager internally)
0243
pnpm @pnpm.io · 12/05/2026
@e18e.dev already works on a plugin that will work with pnpm install
180
pnpm @pnpm.io · 12/05/2026
Is there anything else we can/should do on the client side to mitigate supply chain attacks?
7340
pnpm @pnpm.io · 05/05/2026
pnpm is only added to the lockfile when devEngines.packageManager field is used. The old "packageManager" field introduced by corepack doesn't modify the lockfile.
130
pnpm @pnpm.io · 05/05/2026
It doesn’t break the lockfile. It adds a new document to the top of the lockfile. This is valid yaml and allows us to only read the top part before switching pnpm versions
130
Reposted by pnpm
Socket @socket.dev · 04/05/2026
🧊 Big release for #JavaScript supply chain security: @pnpm.io 11 now defaults to a 1-day Minimum Release Age, blocks exotic subdependencies, and adds a new Allow Builds model. A strong step toward reducing exposure to fast-moving npm attacks → socket.dev/blog/pnpm-11... #nodejs
socket.dev
pnpm 11 Adds Supply Chain Protection Defaults for Minimum Re...
pnpm 11 turns on a 1-day Minimum Release Age and blocks exotic subdeps by default, adding safeguards against fast-moving supply chain attacks.
14515
Reposted by pnpm
Wes @notwes.bsky.social · 04/05/2026
Glad to see we have many new members of team "node is a dev dependency"
061
pnpm @pnpm.io · 04/05/2026
Why? We don't print a prompt for other dependencies. The runtime is treated as just another dependency. The resolved version is saved in the lockfile together with the integrity checksums. Is it not sufficient? I am not aware of other runtime managers doing this.
120
pnpm @pnpm.io · 04/05/2026
The runtime is saved in the lockfile like any other dependency with resolved version and integrity checksums. Same with the pnpm version specified in devEngines.packageManager.
250
Reposted by pnpm
Wes @notwes.bsky.social · 04/05/2026
devEngines started as @geoffreybooth.bsky.social and I in DMs 2 years ago. It's now supported in @npmjs.bsky.social & @pnpm.io, and later this month will be our recommended way for developers at Netflix to define runtime and package manager versions in their projects. docs.npmjs.com/cli/v11/conf...
docs.npmjs.com
package.json | npm Docs
Specifics of npm's package.json handling
4449
pnpm @pnpm.io · 30/04/2026
Thanks to early feedback we have shipped several fixes. pnpm v11.0.3 is released.
1290
Reposted by pnpm
Evil Martians @evilmartians.com · 29/04/2026
We donated to @pnpm.io as part of our open source donations program. It's the default package manager for many of our frontend engineers. The team behind the 11.0 release did an amazing job of securing pnpm against supply-chain attacks, making it one of the safest package managers out there.
1212
pnpm @pnpm.io · 28/04/2026
Best case scenario in a week. Worst case scenario in a month.
010
pnpm @pnpm.io · 28/04/2026
Why does it matter to you? It is a stable version, we treat it as stable, no breaking changes will be introduced.
100
pnpm @pnpm.io · 28/04/2026
Because update tools would automatically bump it in thousands of projects. If there are issue, we need to be able to handle the volume
110
pnpm @pnpm.io · 28/04/2026
pnpm v11.0.0 is released! The "latest" dist-tag still points to v10, so install it via "pnpm self-update latest-11" github.com/orgs/pnpm/di...
github.com
pnpm 11 · pnpm · Discussion #11377
Migration guide: Migrating from v10 to v11 Highlights Major Node.js 22+ required — support for Node 18, 19, 20, and 21 is dropped, pnpm itself is now pure ESM, and the standalone exe requires glibc...
114626
pnpm @pnpm.io · 27/04/2026
Added pnpm Pacquet to the benchmarks github.com/pnpm/pacquet
1685
pnpm @pnpm.io · 21/04/2026
We’ve cut the release branch for v11.0! From this point on, we are only merging bug fixes. Have you tried the latest v11.0 RC 5? If you've encountered any bugs, please file an issue in the repo or reply to this thread! To try v11, run "pnpm self-update next-11"
0415