pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies
Blog post from Socket
pnpm 11 introduces new supply chain protections aimed at enhancing the security of package installations by default, in response to recent supply chain attacks targeting npm, PyPI, and Packagist. Key features include a Minimum Release Age of 24 hours to delay the resolution of newly published package versions, blocking of exotic subdependencies to prevent unexpected dependency sources, and a new Allow Builds model for managing dependency build scripts. These changes reflect the evolving role of package managers in enforcing security decisions beyond simple dependency resolution. Additionally, pnpm 11 brings several updates, such as native publishing commands, built-in SBOM generation, audit fixes through lockfile updates, improved install performance with a SQLite-backed store index, and isolated global installs. Looking ahead, pnpm v12 plans to introduce a Rust installation engine to further enhance performance, with early benchmarks showing significant speed improvements.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 2,152 | 360 | 101 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.