pnpm 10.0.0 Blocks Lifecycle Scripts by Default
Blog post from Socket
pnpm 10.0.0 introduces significant changes by blocking lifecycle scripts by default to enhance security, addressing risks associated with supply chain attacks like the Rspack incident, which involved cryptomining malware. This update aims to prevent the automatic execution of scripts such as `preinstall` and `postinstall`, allowing only those specified in the `pnpm.onlyBuiltDependencies` field of `package.json`. While the change has been largely supported for its focus on security, it has also sparked debate among developers due to compatibility concerns and the deviation from pnpm's previous positioning as an npm drop-in replacement. Contributors like Brandon Cheng acknowledge the transitional challenges but emphasize the long-term benefits of closing a major design flaw. Additional updates in pnpm 10 include the adoption of SHA256 for hashing algorithms and changes to the `pnpm link` command, enhancing security and consistency.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.