Home / Companies / Socket / Blog / Post Details
Content Deep Dive

pnpm 10.16 Adds New Setting for Delayed Dependency Updates -...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
807
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

In response to a series of supply chain attacks on npm packages, pnpm version 10.16 has introduced a new setting called `minimumReleaseAge`, which enforces a delay before newly published packages can be installed, aiming to protect against zero-hour vulnerabilities while maintaining build stability. This setting specifies a mandatory waiting period, allowing tools like Taze and npm-check-updates to adopt similar features, reflecting a shift towards prioritizing security over immediate package updates in the JavaScript community. The approach involves fetching full package metadata, which may slow down installations but improves caching, and includes features to bypass the delay for trusted or internal packages. While the delay is seen as a buffer against opportunistic attacks, some critics argue it may be inadequate against sophisticated threats, highlighting the need for a balance between security measures and workflow simplicity. Despite the skepticism, these features are increasingly seen as a necessary layer of defense, helping to reduce the risk of malware during the critical initial release period, though not a substitute for comprehensive security practices.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.