pnpm 11.5 Adds Support for Recognizing npm Staged Publishes
Blog post from Socket
pnpm 11.5 addresses a false-positive downgrade warning by treating npm staged publishing approvals as strong trust evidence, reflecting npm's ongoing tightening of package publishing controls after incidents involving credential theft and token abuse. This update resolves an issue where the trustPolicy: no-downgrade setting misclassified staged publishing as a downgrade from trusted publishing due to incorrect inference from the _npmUser field, as reported by Kevin Deng. The fix involves recognizing staged publishing approval as its own strong trust signal, thereby preventing misclassification and reducing unnecessary alerts. This change underscores the need for clearer registry metadata to accurately convey publishing security properties, especially as npm introduces multiple release paths like classic, trusted, and staged publishing modes. Additionally, pnpm 11.5 includes other supply chain updates, such as improved handling of minimumReleaseAgeExclude, preservation of the integrity field for remote dependencies, and enhanced browser-based 2FA handling for specific npm operations, showcasing adaptations to npm's evolving security model.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.