Skip to content

chore(deps): update pnpm to v10.29.1#678

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/pnpm-10.x
Open

chore(deps): update pnpm to v10.29.1#678
renovate[bot] wants to merge 1 commit intomainfrom
renovate/pnpm-10.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 6, 2025

This PR contains the following updates:

Package Change Age Confidence
pnpm (source) 10.18.010.29.1 age confidence

Release Notes

pnpm/pnpm (pnpm)

v10.29.1: pnpm 10.29.1

Compare Source

Minor Changes

  • The pnpm dlx / pnpx command now supports the catalog: protocol. Example: pnpm dlx shx@catalog:.
  • Support configuring auditLevel in the pnpm-workspace.yaml file #​10540.
  • Support bare workspace: protocol without version specifier. It is now treated as workspace:* and resolves to the concrete version during publish #​10436.

Patch Changes

  • Fixed pnpm list --json returning incorrect paths when using global virtual store #​10187.

  • Fix pnpm store path and pnpm store status using workspace root for path resolution when storeDir is relative #​10290.

  • Fixed pnpm run -r failing with "No projects matched the filters" when an empty pnpm-workspace.yaml exists #​10497.

  • Fixed a bug where catalogMode: strict would write the literal string "catalog:" to pnpm-workspace.yaml instead of the resolved version specifier when re-adding an existing catalog dependency #​10176.

  • Fixed the documentation URL shown in pnpm completion --help to point to the correct page at https://pnpm.io/completion #​10281.

  • Skip local file: protocol dependencies during pnpm fetch. This fixes an issue where pnpm fetch would fail in Docker builds when local directory dependencies were not available #​10460.

  • Fixed pnpm audit --json to respect the --audit-level setting for both exit code and output filtering #​10540.

  • update tar to version 7.5.7 to fix security issue

    Updating the version of dependency tar to 7.5.7 because the previous one have a security vulnerability reported here: CVE-2026-24842

  • Fix pnpm audit --fix replacing reference overrides (e.g. $foo) with concrete versions #​10325.

  • Fix shamefullyHoist set via updateConfig in .pnpmfile.cjs not being converted to publicHoistPattern #​10271.

  • pnpm help should correctly report if the currently running pnpm CLI is bundled with Node.js #​10561.

  • Add a warning when the current directory contains the PATH delimiter character. On macOS, folder names containing forward slashes (/) appear as colons (:) at the Unix layer. Since colons are PATH separators in POSIX systems, this breaks PATH injection for node_modules/.bin, causing binaries to not be found when running commands like pnpm exec #​10457.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.28.2: pnpm 10.28.2

Compare Source

Patch Changes

  • Security fix: prevent path traversal in directories.bin field.

  • When pnpm installs a file: or git: dependency, it now validates that symlinks point within the package directory. Symlinks to paths outside the package root are skipped to prevent local data from being leaked into node_modules.

    This fixes a security issue where a malicious package could create symlinks to sensitive files (e.g., /etc/passwd, ~/.ssh/id_rsa) and have their contents copied when the package is installed.

    Note: This only affects file: and git: dependencies. Registry packages (npm) have symlinks stripped during publish and are not affected.

  • Fixed optional dependencies to request full metadata from the registry to get the libc field, which is required for proper platform compatibility checks #​9950.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.28.1

Compare Source

v10.28.0

Compare Source

v10.27.0

Compare Source

v10.26.2: pnpm 10.26.2

Compare Source

Patch Changes

  • Improve error message when a package version exists but does not meet the minimumReleaseAge constraint. The error now clearly states that the version exists and shows a human-readable time since release (e.g., "released 6 hours ago") #​10307.

  • Fix installation of Git dependencies using annotated tags #​10335.

    Previously, pnpm would store the annotated tag object's SHA in the lockfile instead of the actual commit SHA. This caused ERR_PNPM_GIT_CHECKOUT_FAILED errors because the checked-out commit hash didn't match the stored tag object hash.

  • Binaries of runtime engines (Node.js, Deno, Bun) are written to node_modules/.bin before lifecycle scripts (install, postinstall, prepare) are executed #​10244.

  • Try to avoid making network calls with preferOffline #​10334.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.26.1: pnpm 10.26.1

Compare Source

Patch Changes

  • Don't fail on pnpm add, when blockExoticSubdeps is set to true #​10324.
  • Always resolve git references to full commits and ensure HEAD points to the commit after checkout #​10310.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.26.0

Compare Source

v10.25.0

Compare Source

v10.24.0

Compare Source

v10.23.0: pnpm 10.23

Compare Source

Minor Changes

  • Added --lockfile-only option to pnpm list #​10020.

Patch Changes

  • pnpm self-update should download pnpm from the configured npm registry #​10205.
  • pnpm self-update should always install the non-executable pnpm package (pnpm in the registry) and never the @pnpm/exe package, when installing v11 or newer. We currently cannot ship @pnpm/exe as pkg doesn't work with ESM #​10190.
  • Node.js runtime is not added to "dependencies" on pnpm add, if there's a engines.runtime setting declared in package.json #​10209.
  • The installation should fail if an optional dependency cannot be installed due to a trust policy check failure #​10208.
  • pnpm list and pnpm why now display npm: protocol for aliased packages (e.g., foo npm:is-odd@3.0.1) #​8660.
  • Don't add an extra slash to the Node.js mirror URL #​10204.
  • pnpm store prune should not fail if the store contains Node.js packages #​10131.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.22.0: pnpm 10.22

Compare Source

Minor Changes

  • Added support for trustPolicyExclude #​10164.

    You can now list one or more specific packages or versions that pnpm should allow to install, even if those packages don't satisfy the trust policy requirement. For example:

    trustPolicy: no-downgrade
    trustPolicyExclude:
      - chokidar@4.0.3
      - webpack@4.47.0 || 5.102.1
  • Allow to override the engines field on publish by the publishConfig.engines field.

Patch Changes

  • Don't crash when two processes of pnpm are hardlinking the contents of a directory to the same destination simultaneously #​10179.

Platinum Sponsors

Bit

Gold Sponsors

Discord CodeRabbit Workleap
Stackblitz Vite

v10.21.0

Compare Source

v10.20.0

Compare Source

Minor Changes
  • Support --all option in pnpm --help to list all commands #​8628.
Patch Changes
  • When the latest version doesn't satisfy the maturity requirement configured by minimumReleaseAge, pick the highest version that is mature enough, even if it has a different major version #​10100.
  • create command should not verify patch info.
  • Set managePackageManagerVersions to false, when switching to a different version of pnpm CLI, in order to avoid subsequent switches #​10063.

v10.19.0

Compare Source

Minor Changes
  • You can now allow specific versions of dependencies to run postinstall scripts. onlyBuiltDependencies now accepts package names with lists of trusted versions. For example:

    onlyBuiltDependencies:
      - nx@21.6.4 || 21.6.5
      - esbuild@0.25.1

    Related PR: #​10104.

  • Added support for exact versions in minimumReleaseAgeExclude #​9985.

    You can now list one or more specific versions that pnpm should allow to install, even if those versions don’t satisfy the maturity requirement set by minimumReleaseAge. For example:

    minimumReleaseAge: 1440
    minimumReleaseAgeExclude:
      - nx@21.6.5
      - webpack@4.47.0 || 5.102.1

v10.18.3

Compare Source

Patch Changes
  • Fix a bug where pnpm would infinitely recurse when using verifyDepsBeforeInstall: install and pre/post install scripts that called other pnpm scripts #​10060.
  • Fixed scoped registry keys (e.g., @scope:registry) being parsed as property paths in pnpm config get when --location=project is used #​9362.
  • Remove pnpm-specific CLI options before passing to npm publish to prevent "Unknown cli config" warnings #​9646.
  • Fixed EISDIR error when bin field points to a directory #​9441.
  • Preserve version and hasBin for variations packages #​10022.
  • Fixed pnpm config set --location=project incorrectly handling keys with slashes (auth tokens, registry settings) #​9884.
  • When both pnpm-workspace.yaml and .npmrc exist, pnpm config set --location=project now writes to pnpm-workspace.yaml (matching read priority) #​10072.
  • Prevent a table width error in pnpm outdated --long #​10040.
  • Sync bin links after injected dependencies are updated by build scripts. This ensures that binaries created during build processes are properly linked and accessible to consuming projects #​10057.

v10.18.2

Compare Source

Patch Changes
  • pnpm outdated --long should work #​10040.
  • Replace ndjson with split2. Reduce the bundle size of pnpm CLI #​10054.
  • pnpm dlx should request the full metadata of packages, when minimumReleaseAge is set #​9963.
  • pnpm version switching should work when the pnpm home directory is in a symlinked directory #​9715.
  • Fix EPIPE errors when piping output to other commands #​10027.

v10.18.1

Compare Source

Patch Changes
  • Don't print a warning, when --lockfile-only is used #​8320.
  • pnpm setup creates a command shim to the pnpm executable. This is needed to be able to run pnpm self-update on Windows #​5700.
  • When using pnpm catalogs and running a normal pnpm install, pnpm produced false positive warnings for "skip adding to the default catalog because it already exists". This warning now only prints when using pnpm add --save-catalog as originally intended.

  • If you want to rebase/retry this PR, check this box

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Oct 6, 2025
@renovate renovate bot requested a review from IgorKowalczyk October 6, 2025 13:49
@renovate renovate bot changed the title chore(deps): update pnpm to v10.18.1 chore(deps): update pnpm to v10.18.2 Oct 10, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 48401a9 to e08ab40 Compare October 10, 2025 01:10
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from e08ab40 to 13df8c7 Compare October 14, 2025 11:15
@renovate renovate bot changed the title chore(deps): update pnpm to v10.18.2 chore(deps): update pnpm to v10.18.3 Oct 14, 2025
@renovate renovate bot changed the title chore(deps): update pnpm to v10.18.3 chore(deps): update pnpm to v10.19.0 Oct 22, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 13df8c7 to f8d9cfd Compare October 22, 2025 02:37
@renovate renovate bot changed the title chore(deps): update pnpm to v10.19.0 chore(deps): update pnpm to v10.20.0 Oct 28, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from f8d9cfd to 338cc61 Compare October 28, 2025 21:04
@renovate renovate bot changed the title chore(deps): update pnpm to v10.20.0 chore(deps): update pnpm to v10.21.0 Nov 10, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 338cc61 to a46bf83 Compare November 10, 2025 03:14
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from a46bf83 to 75773d2 Compare November 12, 2025 20:02
@renovate renovate bot changed the title chore(deps): update pnpm to v10.21.0 chore(deps): update pnpm to v10.22.0 Nov 12, 2025
@renovate renovate bot changed the title chore(deps): update pnpm to v10.22.0 chore(deps): update pnpm to v10.23.0 Nov 20, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 75773d2 to 8b7f9b7 Compare November 20, 2025 17:12
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 8b7f9b7 to e9a49e1 Compare November 27, 2025 15:03
@renovate renovate bot changed the title chore(deps): update pnpm to v10.23.0 chore(deps): update pnpm to v10.24.0 Nov 27, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from e9a49e1 to 7ed2df8 Compare December 6, 2025 11:32
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 7ed2df8 to 58a04b4 Compare December 8, 2025 19:34
@renovate renovate bot changed the title chore(deps): update pnpm to v10.24.0 chore(deps): update pnpm to v10.25.0 Dec 8, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 58a04b4 to ee7dcac Compare December 15, 2025 14:10
@renovate renovate bot changed the title chore(deps): update pnpm to v10.25.0 chore(deps): update pnpm to v10.26.0 Dec 15, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from ee7dcac to afe6573 Compare December 19, 2025 02:47
@renovate renovate bot changed the title chore(deps): update pnpm to v10.26.0 chore(deps): update pnpm to v10.26.1 Dec 19, 2025
@renovate renovate bot changed the title chore(deps): update pnpm to v10.26.1 chore(deps): update pnpm to v10.26.2 Dec 23, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from afe6573 to 895777b Compare December 23, 2025 16:48
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 895777b to eaa0bb7 Compare December 30, 2025 21:54
@renovate renovate bot changed the title chore(deps): update pnpm to v10.26.2 chore(deps): update pnpm to v10.27.0 Dec 30, 2025
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from eaa0bb7 to e5c1b87 Compare January 10, 2026 00:58
@renovate renovate bot changed the title chore(deps): update pnpm to v10.27.0 chore(deps): update pnpm to v10.28.0 Jan 10, 2026
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from e5c1b87 to 3b3af97 Compare January 19, 2026 12:45
@renovate renovate bot changed the title chore(deps): update pnpm to v10.28.0 chore(deps): update pnpm to v10.28.1 Jan 19, 2026
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from 3b3af97 to f6ea629 Compare January 26, 2026 18:46
@renovate renovate bot changed the title chore(deps): update pnpm to v10.28.1 chore(deps): update pnpm to v10.28.2 Jan 26, 2026
@renovate renovate bot changed the title chore(deps): update pnpm to v10.28.2 chore(deps): update pnpm to v10.29.1 Feb 7, 2026
@renovate renovate bot force-pushed the renovate/pnpm-10.x branch from f6ea629 to f4d70ff Compare February 7, 2026 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants