pnpm release notes, breaking changes, and upgrade notes.
Fast, disk space efficient package manager StackPulse turns upstream changelogs into scannable summaries with risky changes, deprecations, migration notes, and source links.
This release improves TLS certificate verification by failing immediately on invalid certificates and enhances macOS compatibility by using bundled certificate roots when system SSL policies fail. It also fixes peer dependency installation issues when `autoInstallPeers` is enabled.
affected
Users on macOS or those with TLS certificate verification issues may experience improved reliability and performance.
action
Update to this version to benefit from improved TLS certificate handling and macOS compatibility fixes.
release_signals
!Requests to registries or tarball servers with invalid TLS certificates now fail immediately instead of retrying.
!Improved SSL policy handling on macOS to prevent crashes during registry requests.
+pnpr config file now supports `${VAR?}` placeholders for environment variables.
+Installing through a pnpr server now correctly handles peer dependencies when `autoInstallPeers` is enabled.
This release introduces the `forceIgnoresPlatform` setting and `pnpm update --peer`, while addressing numerous bugs in `pnpm deploy`, `--filter`, `nodeLinker: hoisted`, and custom `modulesDir` setups. It also includes critical security fixes for shell completion, bin shims on Nix, lifecycle scripts inside custom `modulesDir`, and `userAgent` placeholders in `pnpm-workspace.yaml`.
affected
Users relying on custom `modulesDir`, shell completion, or environment variables in `pnpm-workspace.yaml` are affected by security fixes.
action
Update to pnpm 11.28.0 to benefit from security fixes and new features.
release_signals
!Fixed environment variable expansion in `userAgent` within `pnpm-workspace.yaml` to prevent sending sensitive data to registries.
!Prevented lifecycle scripts from running in custom `modulesDir` without `allowBuilds` approval.
v12.7.0highfeaturesecuritySep 25, 2026
pnpm 12.7
pnpm 12.7.0 introduces support for `.nvmrc` and `.node-version` in the global `node` shim, adds new features like `--allow-build` and `--publish-wait-timeout`, and includes several security fixes for bin shims and lifecycle scripts.
affected
Users of pnpm with security-sensitive environments or those relying on specific Node.js version management will benefit from the security fixes and new features.
action
Update to pnpm 12.7.0 to benefit from new features and security fixes.
release_signals
!Fixed environment variable expansion in `userAgent` set in `pnpm-workspace.yaml`.
!Secured bin shims on Nix to prevent redirection of system utilities.
!Prevented lifecycle scripts of packages in `storeDir` from running without `allowBuilds` approval.
v12.6.0highfeaturesecuritySep 22, 2026
pnpm 12.6
This release introduces automatic dependency deduplication, relocatable node_modules, and support for saving TypeScript types alongside dependencies. It also includes several security fixes and improvements to package installation and dependency resolution.
affected
Users who rely on dependency deduplication, TypeScript types, or relocatable `node_modules` directories will benefit from this release.
action
Update to pnpm 12.6.0 to take advantage of new features and security improvements.
release_signals
!POSIX bin shims now take `cygpath` and `wslpath` from the system default path on Cygwin, MSYS2, and WSL2
!`pnpm install` warnings no longer carry the text of a package's deprecation notice
!Commands now warn when environment variables in project `.npmrc` credentials are ignored
v12.4.2highfeaturesecuritySep 15, 2026
pnpm 12.4.2
pnpm 12.4.2 includes security fixes for executable shims and GitHub Actions links, improves reliability of installs, and speeds up peer dependency checks in workspaces. It also enhances Python lockfiles to work across compatible targets.
affected
Users on FreeBSD, Windows, and macOS may experience improved reliability and security, particularly those using executable shims or GitHub Actions.
action
Reinstall dependencies to replace existing shims for security fixes.
release_signals
!Dependency executables can no longer take over another package's POSIX bin shim through its shell helpers.
!GitHub Actions homepage links no longer expose server credentials; GitHub server URLs now require HTTPS.
+
v11.27.0mediumfeaturesecuritySep 12, 2026
pnpm 11.27
This release introduces global configuration for Node.js download mirrors and a new workspace trust policy setting. It also includes several bug fixes and security improvements.
affected
Users who need to configure Node.js download mirrors or manage workspace trust policies are affected.
action
Update to pnpm v11.27.0 to benefit from new features and fixes.
release_signals
!Fixed a security issue where a downloaded runtime archive was unpacked into a predictable path, now uses a randomly named directory inside the store (GHSA-vwc7-r8mq-g2x9).
+`nodeDownloadMirrors` can now be set in the global config file (`config.yaml`) and through the `PNPM_CONFIG_NODE_DOWNLOAD_MIRRORS` environment variable.
This release primarily fixes installation issues on filesystems that refuse hard links or clones, such as Android, EdenFS, and rootless containers. It also improves performance for repeat installs and adds support for more flexible directory selectors.
affected
Users on filesystems that refuse hard links or clones (like Android, EdenFS, or rootless containers) and those using `nodeLinker: hoisted` are affected by the fixes in this release.
action
Update to pnpm 12.4.1 to benefit from the fixes and performance improvements, especially if you encounter filesystem-related installation issues.
release_signals
!pnpm now uses bundled CA certificates on Android to prevent registry request crashes due to missing system CA certificates.
+pnpm install now falls back to copying when hard links or clones are refused by the filesystem.
v11.26.0mediumfeaturesecuritySep 6, 2026
pnpm 11.26
This release introduces new features like workspace dependency resolution via the `workspace:` protocol and CI validation with `pnpm change check`. It also includes several security and bug fixes, such as hiding sensitive data in logs and improving audit functionality.
affected
Users leveraging workspace dependencies, CI validation, or security-sensitive operations will benefit from the new features and fixes.
action
Update to pnpm v11.26.0 to take advantage of new features and fixes.
release_signals
!Fetch and tarball errors and retry logs now hide URL credentials, query strings, and fragments that could expose secrets.
!`pnpm audit` now excludes ignored advisories from vulnerability totals and severity counts, and reports them separately.
!
Secured bin shims on Nix to avoid redirection by system utility-named dependencies.
!Improved shell completion to omit control or invisible formatting characters.
!Prevented re-running scripts named `pnpm` or `pn` as though they were pnpm.
+Added the `forceIgnoresPlatform` setting to control optional dependency installation during `pnpm install --force`.
+Introduced `pnpm update --peer` for updating peer dependencies.
+Support for bzip2 compressed tarballs in `pnpm add` and `pnpm install`.
+Improved handling of git dependencies with committed submodules.
+Enhanced `pnpm install` to reinstall projects moved or renamed with their `node_modules`.
Catalogs can now resolve workspace dependencies through the `workspace:` protocol.
+`pnpm remove` and `pnpm update` now accept `--trust-lockfile`, `--no-trust-lockfile`, `--trust-policy`, `--trust-policy-exclude`, and `--trust-policy-ignore-after`.
+Added `pnpm change check` for CI validation of package versions against the `versioning.epics` bands and `versioning.fixed` groups in `pnpm-workspace.yaml`.