what stackpulse tracks
pnpm releases from GitHub
StackPulse watches pnpm release notes and keeps the original source link close to every summary.
Fast, disk space efficient package manager StackPulse turns upstream changelogs into scannable summaries with risky changes, deprecations, migration notes, and source links.
what stackpulse tracks
StackPulse watches pnpm release notes and keeps the original source link close to every summary.
upgrade risk
Risky changes are separated from normal feature notes so you can scan upgrade impact before changing production dependencies.
migration notes
Migration steps and recommended actions are only shown when the upstream release notes support them.
This release addresses a critical security vulnerability in projects using `namedRegistries` by introducing registry-qualified keys in the lockfile. It also adds a built-in `npmjs:` alias and improves dependency resolution performance.
Projects using `namedRegistries` are affected by the security fix and lockfile format change.
Upgrade to pnpm v11.20.0 immediately if using `namedRegistries` to mitigate package substitution risks.
This release introduces a critical security fix for projects using `namedRegistries` in pnpm 11.1.0–11.19.x, addressing a package-substitution vulnerability. It also includes performance improvements for workspace installations and peer dependency resolution.
Projects using `namedRegistries` in pnpm 11.1.0–11.19.x are affected by the security fix and must upgrade.
Upgrade to pnpm 12 Beta 4 and perform a non-frozen install to re-key lockfile entries.
This release introduces a new `update.githubActionsServer` setting for custom GitHub server URLs, adds the `pnpm unpublish` command, and improves handling of GitHub Actions dependencies. It also includes several patches addressing token polling security, `pnpm install --no-runtime`, and `pnpm update --latest` behavior.
Users relying on GitHub Actions dependencies or needing to unpublish packages will benefit from the new features.
Update to this version to take advantage of new features and security improvements.
This release introduces a new setting for GitHub Actions server URL configuration, improves handling of GitHub Actions dependencies, and includes several bug fixes and security enhancements.
Users relying on GitHub Actions or web-based authentication may be affected by the changes.
Update to version 11.17.0 to benefit from the new features and security improvements.