Skip to content

chore(deps): update pnpm to v12 - #710

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pnpm-12.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pnpm-12.x

Conversation

@renovate

@renovate renovate Bot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
pnpm (source) 10.18.0 → 12.11.2 age confidence

Release Notes

pnpm/pnpm (pnpm)

v12.11.2: pnpm 12.11.2

Compare Source

This release fixes --workspace-concurrency=Infinity, filters set by an updateConfig hook, and store fetches with enable-modules-dir=false.

Patch Changes
  • --workspace-concurrency=Infinity now runs workspace projects with no concurrency limit. It used to fail with invalid digit found in string #​16793.

  • pnpm install and other recursive commands now apply the filter and filterProd that an updateConfig hook sets. They used to run on every workspace project #​16792.

  • enable-modules-dir=false now also fetches the packages an install reuses from an existing lockfile, so the store holds every package the lockfile lists.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.11.1: pnpm 12.11.1

Compare Source

This release fixes two ways pnpm install could fail, runs tools of any Rust release through pnx, and treats registry.npmjs.com as an alias of the npm registry.

Patch Changes
  • pnpm install no longer fails when packageManager pins the pnpm version that is already running and the registry does not publish that version. pnpm warns and continues. A registry mirror that has not synced a release no longer blocks the commands of a project pinned to it.

  • pnpm install no longer fails with ERR_PNPM_CMD_SHIM_CHMOD when node_modules/.bin holds a shim that another user created, if everyone can already execute it and it is not world-writable. This happens when several users share one checkout.

  • enable-modules-dir=false (enableModulesDir: false through the Node.js addon) fetches the registry packages the host can install into the store again, as pnpm v10 did, while still writing nothing under node_modules. The setting exists for a node_modules that something else mounts from the store, such as a FUSE daemon, and that consumer no longer has to download each package on first access. A plain --lockfile-only run still fetches nothing.

  • pnpm pack and pnpm publish no longer put .npmignore and .gitignore files in the tarball. A files entry that names one still ships it.

  • pnpm now treats https://registry.npmjs.com/ as an alias of https://registry.npmjs.org/. Registry requests, credentials, and trusted publishing use the canonical hostname.

  • pnx --package=rust@<channel> <tool> runs a tool of that Rust release, for example pnx --package=rust@nightly-2026-01-01 cargo build. pnpm installs the release with the components and targets from rust-toolchain.toml and the target of each --target argument.

  • pnpm install now links agent skills for more coding agents. It detects the agent from ANTIGRAVITY_AGENT, COPILOT_AGENT, COPILOT_CLI, CODEX_THREAD_ID, CODEX_SANDBOX, AI_AGENT, and CLAUDE_CODE pnpm/tasks#116.

  • When the registry rejects pnpm stage publish, the error message now starts with "Failed to stage package".

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.11.0: pnpm 12.11.0

Compare Source

This release adds Rust toolchain management, links the agent skills that dependencies ship, adds the permissions setting, and keeps the colors of streamed script output.

Minor Changes
  • pnpm install now links the agent skills that direct dependencies ship under skills/<name>/SKILL.md into the project's agent skill directories, such as .claude/skills. A package's skills are linked only after you approve them with pnpm approve. The skills.dirs setting chooses the directories pnpm/rfcs#35.

    Added the permissions setting, which records what each dependency may do. Its build capability works like allowBuilds and takes precedence over it. pnpm approve-builds writes to permissions when pnpm-workspace.yaml already has it, and to allowBuilds otherwise.

    Added pnpm permissions, which lists the granted and denied permissions and the packages awaiting approval. pnpm approve reviews build scripts and agent skills in one prompt pnpm/rfcs#36.

  • pnpm now installs and runs Rust toolchains.

    • With cargo.enabled, pnpm install installs the toolchain named in rust-toolchain.toml. pnpm verifies the release signature, stores the toolchain once per machine, and links it into .pnpm/rust. pnpm run and pnpm exec put its cargo and rustc on the PATH.
    • pnpm add -g rust@<channel> installs a toolchain globally. The cargo and rustc commands run it outside projects that pin their own. pnpm update -g, pnpm ls -g, and pnpm remove -g manage it like any global package.
    • In a project, pnpm add rust@<channel> pins the toolchain in rust-toolchain.toml.
    • pnpm shim add rust adds project-aware shims for cargo, rustc, and the other Rust tools. In a project with a rust-toolchain.toml, they run the toolchain the file names and install it on first use. Elsewhere, the next command of the same name on PATH runs, such as rustup's.
  • pnpm run and pnpm exec now keep the colors of script output that they print under the project's name, such as with --stream. pnpm sets FORCE_COLOR=1 for these scripts when its own output is in color, unless FORCE_COLOR is already set.

    Script output is also rendered more cleanly:

    • A line that a progress bar redraws with \r shows only its last state.
    • Escape codes that move the cursor or clear the screen are dropped.
    • Long colored lines are cut at the terminal width.
    • pnpm -r run no longer garbles its live output when a script fails while other scripts are still running.
Patch Changes
Installing packages
  • pnpm no longer panics with "unexpected error when polling the I/O driver" when it runs under QEMU user-mode emulation, such as a linux/amd64 container on an Apple Silicon Mac #​16696.

  • pnpm view, pnpm update, and other commands that read registry metadata now work behind proxies that end a response by closing the connection without a TLS close_notify alert #​16704.

  • pnpm now switches to the version a project pins in packageManager or devEngines.packageManager even when pnpm-workspace.yaml has a setting the running pnpm cannot read, such as a lockfile.includeResolutionSettings section. If pnpm does not switch, it still reports that setting #​16675.

  • When the pnpm package has to download its native binary on first run, it now uses the registry and credentials from .npmrc and from the npm_config_registry and pnpm_config_registry environment variables. COREPACK_NPM_REGISTRY still takes precedence. A project .npmrc is not read when COREPACK_INTEGRITY_KEYS turns off the signature check #​16655.

  • pnpm install and pnpm add --config now apply minimumReleaseAge when they resolve a config dependency. A config dependency range resolves to the newest version that is old enough, so a later clean pnpm install --frozen-lockfile accepts the lockfile #​16660.

  • pnpm remove with catalogPrune no longer removes catalog entries that pnpm-lock.yaml still records for workspace projects missing from disk. Before, a following frozen install failed with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH #​16679.

  • With cargo.enabled, pnpm install now writes the source replacement for vendored crates into .pnpm/crates/config.toml and includes it as optional from .cargo/config.toml. A checkout without .pnpm builds with plain Cargo #​16659.

  • With nodeLinker.type set to loaded, Node.js now stops with ERR_PNPM_LOADER_UNSUPPORTED_NODE when it preloads the store loader on a version the loader cannot serve. The supported versions are ^24.18.0 || >=26.2.0. On other versions, CommonJS packages imported from ESM failed with Cannot find module on their first relative require().

  • On Windows, pnpm install no longer fails with "The filename, directory name, or volume label syntax is incorrect" when a package contains a file whose name is invalid on Windows, such as icon.svg?as=metadata.d.ts. pnpm removes the invalid characters from the name and prints a warning that lists the renamed files.

  • On Windows, hoisting no longer fails intermittently with link errors when a junction is created or replaced concurrently pnpm/tasks#53.

Resolving dependencies
  • pnpm install --no-optional now installs the pe

❗ Important

✂ PR body was truncated to here.


Configuration, setup, and pnpm versions

  • pnpm config get --global and pnpm config list --global now show only the global configuration, also when run inside a project. Settings from the project's pnpm-workspace.yaml and .npmrc were included before. The same applies to --location=global #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the packageManager field pins it. Since 12.9.0 they failed with SyntaxError: Invalid or unexpected token #​16594.

  • On Windows, pnpm self-update no longer runs the update a second time when it replaces a pnpm.cmd linked by pnpm 12.8 or older. cmd.exe read on in the replaced pnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #​16573.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config #​16635.

  • pnpm setup now names the shell config file even if it is already up to date #​16608.

Updating, auditing, and publishing
  • pnpm update --latest now applies the savePrefix setting when it rewrites a dependency whose range has no operator of its own, such as <2.0.0.

  • The interactive pnpm audit --fix picker now shows each patched version with the saveExact and savePrefix style that the override is written with #​13209.

  • pnpm unpublish <pkg>@<version> now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #​16568. It also no longer mistakes a sibling path such as /npm-mirror/ for the registry path /npm/ pnpm/tasks#94.

Output and messages
  • A warning about a project's devEngines or packageManager pin is now printed to stderr. A command such as pnpm cache path or pnpm list --json keeps only its own output on stdout #​16584.

  • pnpm list now reports the correct package paths when nodeLinker is hoisted #​9593.

  • Resolution errors now name the failing dependency and its parent packages. Fatal errors appear as structured error records with their error codes when using --reporter=ndjson.

  • The error for an invalid git repository in the lockfile now has the code ERR_PNPM_INVALID_GIT_REPOSITORY. Its message now lists every rejected form of the value.

  • pnpm runtime --help and pnpm help runtime now name the set subcommand and the runtimes it accepts #​16580.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.9.1: pnpm 12.9.1

Compare Source

This release moves the WebContainer build into a separate @pnpm/wasm package, shrinks the pnpm package back to about 4 MB, and fixes pnpm publish with provenance from GitLab CI.

Patch Changes
  • The WebAssembly build for StackBlitz WebContainers now ships as a separate @pnpm/wasm package. The pnpm and @pnpm/exe packages no longer include it, which brings their unpacked size back from about 55 MB to about 4 MB. In a WebContainer, install @pnpm/wasm with npm to get the pnpm command.

  • pnpm publish with provenance from GitLab CI is no longer rejected by the npm registry with a 422 error. The provenance statement now includes the GitLab CI variables in invocation.parameters, as npm does #​16551.

  • pnpm audit signatures now uses the TLS settings of the redirect target when a registry redirects its signing-keys request, for example to registry.npmjs.org. A cafile scoped to a private registry no longer makes the redirected request fail #​16541.

  • Fixed pnpm install --frozen-lockfile rejecting an up-to-date lockfile when an injected workspace package uses a catalog entry in peerDependencies #​16557.

  • The [<since>] filter selector works again with Git 2.24 through 2.27 #​16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.

    It also detects changes in projects whose directory names contain non-ASCII characters. Such a change used to be credited to the parent project. changedFilesIgnorePattern and testPattern now match changed files whose names contain non-ASCII characters.

  • The pnpm executable is about 10% smaller. On macOS arm64 it went from 45.1 MB to 40.3 MB.

  • Sped up trust downgrade checks for packages with long release histories.

  • With optimisticRepeatInstall: false, pnpm install now runs the projects' own lifecycle scripts, such as prepare, even when node_modules is already up to date #​16545.

  • pnpm self-update now fails for Homebrew-installed pnpm and prints the brew upgrade command for the installed formula, such as brew upgrade pnpm or brew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #​16547.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.9.0

Compare Source

v12.8.2

Compare Source

v12.8.1

Compare Source

v12.8.0

Compare Source

v12.7.0

Compare Source

v12.6.0

Compare Source

v12.5.1

Compare Source

v12.5.0

Compare Source

v12.4.2

Compare Source

v12.4.1

Compare Source

v12.4.0

Compare Source

v12.3.4

Compare Source

v12.3.3

Compare Source

v12.3.2

Compare Source

v12.3.1

Compare Source

v12.3.0

Compare Source

v12.2.1

Compare Source

v12.2.0

Compare Source

v12.1.0

Compare Source

v12.0.0

Compare Source

v11.28.5

Compare Source

v11.28.4

Compare Source

v11.28.3

Compare Source

v11.28.2

Compare Source

v11.28.1

Compare Source

v11.28.0

Compare Source

v11.27.1

Compare Source

v11.27.0

Compare Source

v11.26.0

Compare Source

v11.25.0

Compare Source

v11.24.0

Compare Source

v11.23.0

Compare Source

v11.22.0

Compare Source

v11.21.0

Compare Source

v11.20.0

Compare Source

v11.19.0

Compare Source

v11.18.0

Compare Source

v11.17.0

Compare Source

v11.16.0

Compare Source

v11.15.1

Compare Source

v11.15.0

Compare Source

v11.14.0

Compare Source

v11.13.1

Compare Source

v11.13.0

Compare Source

v11.12.0

Compare Source

v11.11.0

Compare Source

v11.10.0

Compare Source

v11.9.0

Compare Source

v11.8.0

Compare Source

v11.7.0

Compare Source

v11.6.0

Compare Source

v11.5.3

Compare Source

v11.5.2

Compare Source

v11.5.1

Compare Source

v11.5.0

Compare Source

v11.4.0

Compare Source

v11.3.0

Compare Source

v11.2.2

Compare Source

v11.2.1

Compare Source

v11.2.0

Compare Source

v11.1.3

Compare Source

v11.1.2

Compare Source

v11.1.1

Compare Source

v11.1.0

Compare Source

v11.0.9

Compare Source

v11.0.8

Compare Source

v11.0.7

Compare Source

v11.0.6

Compare Source

v11.0.5

Compare Source

v11.0.4

Compare Source

v11.0.3

Compare Source

v11.0.2

Compare Source

v11.0.1

Compare Source

v11.0.0

Compare Source

v10.34.6

Compare Source

v10.34.5

Compare Source

v10.34.4

Compare Source

v10.34.3

Compare Source

v10.34.2

Compare Source

v10.34.1

Compare Source

v10.34.0

Compare Source

v10.33.4

Compare Source

v10.33.3

Compare Source

v10.33.2

Compare Source

v10.33.1

Compare Source

v10.33.0

Compare Source

v10.32.1

Compare Source

v10.32.0

Compare Source

v10.31.0

Compare Source

v10.30.3

Compare Source

v10.30.2

Compare Source

v10.30.1

Compare Source

v10.30.0

Compare Source

v10.29.3

Compare Source

v10.29.2

Compare Source

v10.29.1

Compare Source

v10.28.2

Compare Source

v10.28.1

Compare Source

v10.28.0

Compare Source

v10.27.0

Compare Source

v10.26.2

Compare Source

v10.26.1

Compare Source

v10.26.0

Compare Source

v10.25.0

Compare Source

v10.24.0

Compare Source

v10.23.0

Compare Source

v10.22.0

Compare Source

v10.21.0

Compare Source

v10.20.0

Compare Source

v10.19.0

Compare Source

v10.18.3

Compare Source

v10.18.2

Compare Source

v10.18.1

Compare Source


  • If you want to rebase/retry this PR, check this box

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 5, 2026
@renovate
renovate Bot requested a review from IgorKowalczyk September 5, 2026 22:08
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from b512165 to 979057d Compare September 11, 2026 20:42
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from 979057d to 6ffd97d Compare September 16, 2026 11:03
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from 6ffd97d to bd5d686 Compare September 20, 2026 05:59
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from bd5d686 to ccdb6c0 Compare September 24, 2026 01:50
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from ccdb6c0 to dcba3d3 Compare September 29, 2026 18:34
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from dcba3d3 to 0416df9 Compare October 4, 2026 01:38
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from 0416df9 to e454fc5 Compare October 5, 2026 00:49
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from e454fc5 to bd0fc21 Compare October 7, 2026 18:24
@renovate
renovate Bot force-pushed the renovate/pnpm-12.x branch from bd0fc21 to 54c7ac3 Compare October 10, 2026 17:06

This branch had an error being deployed

1 failed deployment
Preview — aceeded8 Deployed Oct 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants