PNpM CLI
This release adds Rust toolchain management, links the agent skills that dependencies ship, adds the permissions setting, and keeps the colors of streamed script output.
Minor Changes
-
pnpm installnow links the agent skills that direct dependencies ship underskills/<name>/SKILL.mdinto the project's agent skill directories, such as.claude/skills. A package's skills are linked only after you approve them withpnpm approve. Theskills.dirssetting chooses the directories pnpm/rfcs#35.Added the
permissionssetting, which records what each dependency may do. Itsbuildcapability works likeallowBuildsand takes precedence over it.pnpm approve-buildswrites topermissionswhenpnpm-workspace.yamlalready has it, and toallowBuildsotherwise.Added
pnpm permissions, which lists the granted and denied permissions and the packages awaiting approval.pnpm approvereviews build scripts and agent skills in one prompt pnpm/rfcs#36. -
pnpm now installs and runs Rust toolchains.
- With
cargo.enabled,pnpm installinstalls the toolchain named inrust-toolchain.toml. pnpm verifies the release signature, stores the toolchain once per machine, and links it into.pnpm/rust.pnpm runandpnpm execput itscargoandrustcon thePATH. pnpm add -g rust@<channel>installs a toolchain globally. Thecargoandrustccommands run it outside projects that pin their own.pnpm update -g,pnpm ls -g, andpnpm remove -gmanage it like any global package.- In a project,
pnpm add rust@<channel>pins the toolchain inrust-toolchain.toml. pnpm shim add rustadds project-aware shims forcargo,rustc, and the other Rust tools. In a project with arust-toolchain.toml, they run the toolchain the file names and install it on first use. Elsewhere, the next command of the same name onPATHruns, such as rustup's.
- With
-
pnpm runandpnpm execnow keep the colors of script output that they print under the project's name, such as with--stream. pnpm setsFORCE_COLOR=1for these scripts when its own output is in color, unlessFORCE_COLORis already set.Script output is also rendered more cleanly:
- A line that a progress bar redraws with
\rshows only its last state. - Escape codes that move the cursor or clear the screen are dropped.
- Long colored lines are cut at the terminal width.
pnpm -r runno longer garbles its live output when a script fails while other scripts are still running.
- A line that a progress bar redraws with
Patch Changes
Installing packages
-
pnpm no longer panics with "unexpected error when polling the I/O driver" when it runs under QEMU user-mode emulation, such as a
linux/amd64container on an Apple Silicon Mac #16696. -
pnpm view,pnpm update, and other commands that read registry metadata now work behind proxies that end a response by closing the connection without a TLSclose_notifyalert #16704. -
pnpm now switches to the version a project pins in
packageManagerordevEngines.packageManagereven whenpnpm-workspace.yamlhas a setting the running pnpm cannot read, such as alockfile.includeResolutionSettingssection. If pnpm does not switch, it still reports that setting #16675. -
When the
pnpmpackage has to download its native binary on first run, it now uses the registry and credentials from.npmrcand from thenpm_config_registryandpnpm_config_registryenvironment variables.COREPACK_NPM_REGISTRYstill takes precedence. A project.npmrcis not read whenCOREPACK_INTEGRITY_KEYSturns off the signature check #16655. -
pnpm installandpnpm add --confignow applyminimumReleaseAgewhen they resolve a config dependency. A config dependency range resolves to the newest version that is old enough, so a later cleanpnpm install --frozen-lockfileaccepts the lockfile #16660. -
pnpm removewithcatalogPruneno longer removes catalog entries thatpnpm-lock.yamlstill records for workspace projects missing from disk. Before, a following frozen install failed withERR_PNPM_LOCKFILE_CONFIG_MISMATCH#16679. -
With
cargo.enabled,pnpm installnow writes the source replacement for vendored crates into.pnpm/crates/config.tomland includes it as optional from.cargo/config.toml. A checkout without.pnpmbuilds with plain Cargo #16659. -
With
nodeLinker.typeset toloaded, Node.js now stops withERR_PNPM_LOADER_UNSUPPORTED_NODEwhen it preloads the store loader on a version the loader cannot serve. The supported versions are^24.18.0 || >=26.2.0. On other versions, CommonJS packages imported from ESM failed withCannot find moduleon their first relativerequire(). -
On Windows,
pnpm installno longer fails with "The filename, directory name, or volume label syntax is incorrect" when a package contains a file whose name is invalid on Windows, such asicon.svg?as=metadata.d.ts. pnpm removes the invalid characters from the name and prints a warning that lists the renamed files. -
On Windows, hoisting no longer fails intermittently with link errors when a junction is created or replaced concurrently pnpm/tasks#53.
Resolving dependencies
-
pnpm install --no-optionalnow installs the peer dependencies a project declares whenautoInstallPeersis on. The lockfile marked such a peeroptional: truewhen another dependency had it as an optional peer. -
pnpm installandpnpm dedupenow link an optional peer to the workspace package that the workspace root depends on when the picked version matches it. They installed the registry package with the same name and version #16706. -
Removal overrides such as
"debug>supports-color": "-"now also apply to an optional peer that a package declares only inpeerDependenciesMeta#16681. -
pnpm addand other installs that re-resolve dependencies now keep the lockeddevEngines.runtimeversion while it still satisfies the declared range #16764. -
pnpm audit --fix updatenow updates only the dependencies whose locked version is vulnerable #14928. -
pnpm outdatedandpnpm update --interactivenow applyoverridesbefore they look up the latest version. Before, a dependency overridden to an npm alias was compared with the latest version of the package the override replaces #16719.
Patched dependencies
-
Patches saved with CRLF line endings now apply, including a patch that creates or deletes a file. pnpm rejected the git headers of such a patch with
ERR_PNPM_INVALID_PATCHand the messageinvalid file mode: 100644#16641. -
A patch that changes a file's mode, such as adding or removing the executable bit, now applies the new mode on Unix pnpm/tasks#110.
Injected dependencies and deploy
-
With
sharedWorkspaceLockfile: false, an injected workspace package installed in the same run as its dependent now holds only the files itsfilesfield selects. The copy also held other files of the project, such astsconfig.json#16683. -
A script listed in
syncInjectedDepsAfterScriptsno longer fails when it rewritespackage.jsonwhile pnpm is copying its edits into the injected copies. The sync after the script now replaces a half-copied manifest. -
pnpm deploywith a shared lockfile no longer fails withERR_PNPM_LOCKFILE_CONFIG_MISMATCHforsettings.dedupeInjectedDepsorsettings.dedupePeerDependentswhenlockfile.includeResolutionSettingsis enabled. The deployed lockfile now records both settings asfalse, the values the deploy installs with. -
pnpm deploynow writes the dependencies in the deployedpackage.jsonsorted by name. It also sorts theallowBuildsentries in the deployedpnpm-workspace.yaml. Repeated deploys of the same lockfile now produce identical files #16687.
Packing and publishing
-
pnpm packandpnpm publishnow match.npmignoreand.gitignorerules the way npm does. A negation such as!lib/**or!lib/**/!(*.map)re-includes files under a directory that an earlier*rule excluded #16743. -
pnpm packandpnpm publishno longer always include root files that merely start withREADME,LICENSE, orLICENCE, such asREADME_INTERNAL.md. OnlyREADME,LICENSE,LICENCE, andCOPYING, with or without an extension, ship regardless offilesand.npmignore, as in npm #16753. -
pnpm publish --provenance=falseand--no-provenancenow turn off provenance under trusted publishing, so a package can be published from a self-hosted runner. Settingprovenance: falseinpnpm-workspace.yamldoes the same #16721.
Speed and resource use
-
pnpm installhardlinks files from a group-writable or world-writable store again. pnpm copied every file from such a store intonode_modules#16677. -
A repeat
pnpm installno longer imports patched packages and packages with build scripts again when nothing changed. Their builds no longer run again either. This happened whenrecursiveInstallwasfalseor the project had afile:dependency #16705. -
Verifying the lockfile against
trustPolicyandminimumReleaseAgeuses less memory. pnpm no longer keeps every published version's manifest of each checked package in memory until the install ends #16656. -
pnpm rebuild <pkg>andpnpm rebuild --pendingno longer read the manifest of every installed package to find build scripts. Only the selected packages are inspected and built. On a largenode_modulesserved lazily, such as over a network or FUSE mount, this turned a rebuild of a few packages into a fetch of every package. -
pnpm rebuildno longer removes and recreatesnode_moduleswhen the settings recorded innode_modules/.modules.yamldiffer from the current configuration. The rebuild runs the build scripts against the installed packages as they are. -
pnpm store prunenow compacts the store'sindex.dbafter removing package entries, so the file shrinks again #16717.
Registry commands
-
pnpm whoami,pnpm bugs,pnpm docs,pnpm repo,pnpm star,pnpm unstar, andpnpm starsnow honor the--registryoption. -
--registrynow takes precedence over a scope's configured registry for scoped packages inpnpm access,pnpm view,pnpm repo,pnpm star,pnpm unstar,pnpm owner,pnpm deprecate,pnpm undeprecate,pnpm unpublish,pnpm dist-tag,pnpm team, andpnpm stage. Without--registry,pnpm accessnow sends a scoped package or scope to the registry configured for that scope. -
Registry commands now keep the path of a registry URL such as
https://example.com/npm/when they build request URLs. This applies topnpm access,pnpm owner,pnpm ping,pnpm search,pnpm star,pnpm stars,pnpm team,pnpm unstar, andpnpm whoami. -
pnpm viewnow honors the network retry settings. -
pnpm reponow fetches the repository URLs of several packages in parallel.
<!-- sponsors -->
Platinum Sponsors
<table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://bit.cloud/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/bit.svg" width="80" alt="Bit"></a> </td> <td align="center" valign="middle"> <a href="https://openai.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/openai_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/openai_light.svg" /> <img src="https://pnpm.io/img/users/openai_dark.svg" width="160" alt="OpenAI" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://notion.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/notion.svg" width="80" alt="Notion"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://coderabbit.ai/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/coderabbit.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/coderabbit_light.svg" /> <img src="https://pnpm.io/img/users/coderabbit.svg" width="220" alt="CodeRabbit" /> </picture> </a> </td> </tr> </tbody> </table>
Gold Sponsors
<table> <tbody> <tr> <td align="center" valign="middle"> <a href="https://sanity.io/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/sanity.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/sanity_light.svg" /> <img src="https://pnpm.io/img/users/sanity.svg" width="120" alt="Sanity" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://discord.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/discord.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/discord_light.svg" /> <img src="https://pnpm.io/img/users/discord.svg" width="220" alt="Discord" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://vite.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/vitejs.svg" width="42" alt="Vite"></a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://serpapi.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/serpapi_dark.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/serpapi_light.svg" /> <img src="https://pnpm.io/img/users/serpapi_dark.svg" width="160" alt="SerpApi" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://stackblitz.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/stackblitz.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/stackblitz_light.svg" /> <img src="https://pnpm.io/img/users/stackblitz.svg" width="190" alt="Stackblitz" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://workleap.com/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/workleap.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/workleap_light.svg" /> <img src="https://pnpm.io/img/users/workleap.svg" width="190" alt="Workleap" /> </picture> </a> </td> </tr> <tr> <td align="center" valign="middle"> <a href="https://nx.dev/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"> <picture> <source media="(prefers-color-scheme: light)" srcset="https://pnpm.io/img/users/nx.svg" /> <source media="(prefers-color-scheme: dark)" srcset="https://pnpm.io/img/users/nx_light.svg" /> <img src="https://pnpm.io/img/users/nx.svg" width="50" alt="Nx" /> </picture> </a> </td> <td align="center" valign="middle"> <a href="https://latitude.so/?utm_source=pnpm&utm_medium=release_notes" target="_blank" rel="noopener noreferrer"><img src="https://pnpm.io/img/users/latitude.svg" width="160" alt="Latitude"></a> </td> </tr> </tbody> </table>
<!-- sponsors end -->