Home / Companies / Socket / Blog / Post Details
Content Deep Dive

pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
924
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

pnpm 11 introduces new supply chain protections aimed at enhancing the security of package installations by default, in response to recent supply chain attacks targeting npm, PyPI, and Packagist. Key features include a Minimum Release Age of 24 hours to delay the resolution of newly published package versions, blocking of exotic subdependencies to prevent unexpected dependency sources, and a new Allow Builds model for managing dependency build scripts. These changes reflect the evolving role of package managers in enforcing security decisions beyond simple dependency resolution. Additionally, pnpm 11 brings several updates, such as native publishing commands, built-in SBOM generation, audit fixes through lockfile updates, improved install performance with a SQLite-backed store index, and isolated global installs. Looking ahead, pnpm v12 plans to introduce a Rust installation engine to further enhance performance, with early benchmarks showing significant speed improvements.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 2,152 360 101 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.