Home / Companies / Socket / Blog / Post Details
Content Deep Dive

pnpm 11.5 Adds Support for Recognizing npm Staged Publishes

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
681
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

pnpm 11.5 addresses a false-positive downgrade warning by treating npm staged publishing approvals as strong trust evidence, reflecting npm's ongoing tightening of package publishing controls after incidents involving credential theft and token abuse. This update resolves an issue where the trustPolicy: no-downgrade setting misclassified staged publishing as a downgrade from trusted publishing due to incorrect inference from the _npmUser field, as reported by Kevin Deng. The fix involves recognizing staged publishing approval as its own strong trust signal, thereby preventing misclassification and reducing unnecessary alerts. This change underscores the need for clearer registry metadata to accurately convey publishing security properties, especially as npm introduces multiple release paths like classic, trusted, and staged publishing modes. Additionally, pnpm 11.5 includes other supply chain updates, such as improved handling of minimumReleaseAgeExclude, preservation of the integrity field for remote dependencies, and enhanced browser-based 2FA handling for specific npm operations, showcasing adaptations to npm's evolving security model.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.