PageSourceSearch

https://pnpm.io/assets/js/4f8e82e2.8255480e.js

js pnpm.io collected 2026-09-24 07:23:30 UTC 9,342 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk=self.webpackChunk||[]).push([["22008"],{2874(e,n,i){i.r(n),i.d(n,{assets:()=>l,contentTitle:()=>o,default:()=>a,frontMatter:()=>c,metadata:()=>s,toc:()=>d});var s=i(66859),t=i(91987),r=i(67008);let c={title:"pnpm 10.29",authors:"zkochan",tags:["release"],date:new Date("2026-02-07T00:00:00.000Z")},o,l={authorsImageUrls:[void 0]},d=[{value:"Minor Changes",id:"minor-changes",level:3},{value:"<code>catalog:</code> Protocol in <code>pnpm dlx</code>",id:"catalog-protocol-in-pnpm-dlx",level:4},{value:"<code>auditLevel</code> Setting",id:"auditlevel-setting",level:4},{value:"Bare <code>workspace:</code> Protocol",id:"bare-workspace-protocol",level:4},{value:"Patch Changes",id:"patch-changes",level:3}];function p(e){let n={a:"a",code:"code",h3:"h3",h4:"h4",li:"li",p:"p",pre:"pre",ul:"ul",...(0,r.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsxs)(n.p,{children:["pnpm 10.29 adds ",(0,t.jsx)(n.code,{children:"catalog:"})," protocol support to ",(0,t.jsx)(n.code,{children:"pnpm dlx"}),", allows configuring ",(0,t.jsx)(n.code,{children:"auditLevel"})," in ",(0,t.jsx)(n.code,{children:"pnpm-workspace.yaml"}),", supports a bare ",(0,t.jsx)(n.code,{children:"workspace:"})," specifier, and includes several bug fixes."]}),"\n",(0,t.jsx)(n.h3,{id:"minor-changes",children:"Minor Changes"}),"\n",(0,t.jsxs)(n.h4,{id:"catalog-protocol-in-pnpm-dlx",children:[(0,t.jsx)(n.code,{children:"catalog:"})," Protocol in ",(0,t.jsx)(n.code,{children:"pnpm dlx"})]}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"pnpm dlx"})," / ",(0,t.jsx)(n.code,{children:"pnpx"})," command now supports the ",(0,t.jsx)(n.code,{children:"catalog:"})," protocol, allowing you to reference versions defined in your workspace catalogs:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-sh",children:"pnpm dlx shx@catalog:\n"})}),"\n",(0,t.jsxs)(n.h4,{id:"auditlevel-setting",children:[(0,t.jsx)(n.code,{children:"auditLevel"})," Setting"]}),"\n",(0,t.jsxs)(n.p,{children:[(0,t.jsx)(n.code,{children:"auditLevel"})," can now be configured in the ",(0,t.jsx)(n.code,{children:"pnpm-workspace.yaml"})," file, so you don't need to pass ",(0,t.jsx)(n.code,{children:"--audit-level"})," on every ",(0,t.jsx)(n.code,{children:"pnpm audit"})," invocation ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/pull/10540",children:"#10540"}),":"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-yaml",metastring:'title="pnpm-workspace.yaml"',children:"auditLevel: high\n"})}),"\n",(0,t.jsxs)(n.h4,{id:"bare-workspace-protocol",children:["Bare ",(0,t.jsx)(n.code,{children:"workspace:"})," Protocol"]}),"\n",(0,t.jsxs)(n.p,{children:["A bare ",(0,t.jsx)(n.code,{children:"workspace:"})," specifier without a version range is now supported. It is treated as ",(0,t.jsx)(n.code,{children:"workspace:*"})," and resolves to the concrete version during publish ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/pull/10436",children:"#10436"}),":"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-json",children:'{\n  "dependencies": {\n    "foo": "workspace:"\n  }\n}\n'})}),"\n",(0,t.jsx)(n.h3,{id:"patch-changes",children:"Patch Changes"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["Fixed an out-of-memory error in ",(0,t.jsx)(n.code,{children:"pnpm list"})," (and ",(0,t.jsx)(n.code,{children:"pnpm why"}),") on large dependency graphs by replacing the recursive tree builder with a two-phase approach: a BFS dependency graph followed by cached tree materialization. Duplicate subtrees are now deduplicated in the output ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/pull/10586",children:"#10586"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"allowBuilds"})," not working when set via ",(0,t.jsx)(n.code,{children:".pnpmfile.cjs"})," ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10516",children:"#10516"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["When ",(0,t.jsx)(n.code,{children:"enableGlobalVirtualStore"})," is set, ",(0,t.jsx)(n.code,{children:"pnpm deploy"})," now ignores it and always creates a localized virtual store within the deploy directory to keep it self-contained."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"minimumReleaseAgeExclude"})," not being respected by ",(0,t.jsx)(n.code,{children:"pnpm dlx"})," ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10338",children:"#10338"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"pnpm list --json"})," returning incorrect paths when using global virtual store ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10187",children:"#10187"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"pnpm store path"})," and ",(0,t.jsx)(n.code,{children:"pnpm store status"})," using workspace root for path resolution when ",(0,t.jsx)(n.code,{children:"storeDir"})," is relative ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10290",children:"#10290"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"catalogMode: strict"})," writing the literal string ",(0,t.jsx)(n.code,{children:"catalog:"})," to ",(0,t.jsx)(n.code,{children:"pnpm-workspace.yaml"})," instead of the resolved version specifier when re-adding an existing catalog dependency ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10176",children:"#10176"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Skip local ",(0,t.jsx)(n.code,{children:"file:"})," protocol dependencies during ",(0,t.jsx)(n.code,{children:"pnpm fetch"}),", fixing Docker builds when local directory dependencies are not available ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10460",children:"#10460"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"pnpm audit --json"})," to respect the ",(0,t.jsx)(n.code,{children:"--audit-level"})," setting for both exit code and output filtering ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/pull/10540",children:"#10540"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Updated ",(0,t.jsx)(n.code,{children:"tar"})," to version 7.5.7 to fix a security vulnerability (",(0,t.jsx)(n.a,{href:"https://www.cve.org/CVERecord?id=CVE-2026-24842",children:"CVE-2026-24842"}),")."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"pnpm audit --fix"})," replacing reference overrides (e.g. ",(0,t.jsx)(n.code,{children:"$foo"}),") with concrete versions ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10325",children:"#10325"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed ",(0,t.jsx)(n.code,{children:"shamefullyHoist"})," set via ",(0,t.jsx)(n.code,{children:"updateConfig"})," in ",(0,t.jsx)(n.code,{children:".pnpmfile.cjs"})," not being converted to ",(0,t.jsx)(n.code,{children:"publicHoistPattern"})," ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10271",children:"#10271"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.code,{children:"pnpm help"}
1)," now correctly reports if the currently running pnpm CLI is bundled with Node.js ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10561",children:"#10561"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Added a warning when the current directory contains the PATH delimiter character, which can break ",(0,t.jsx)(n.code,{children:"node_modules/.bin"})," path injection ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10457",children:"#10457"}),"."]}),"\n",(0,t.jsxs)(n.li,{children:["Fixed the documentation URL shown in ",(0,t.jsx)(n.code,{children:"pnpm completion --help"})," to point to the correct page ",(0,t.jsx)(n.a,{href:"https://github.com/pnpm/pnpm/issues/10281",children:"#10281"}),"."]}),"\n"]})]})}function a(e={}){let{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,t.jsx)(n,{...e,children:(0,t.jsx)(p,{...e})}):p(e)}},67008(e,n,i){i.d(n,{R:()=>c,x:()=>o});var s=i(71763);let t={},r=s.createContext(t);function c(e){let n=s.useContext(r);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function o(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:c(e.components),s.createElement(r.Provider,{value:n},e.children)}},66859(e){e.exports=JSON.parse('{"permalink":"/blog/releases/10.29","editUrl":"https://github.com/pnpm/pnpm.io/edit/main/blog/releases/10.29.md","source":"@site/blog/releases/10.29.md","title":"pnpm 10.29","description":"pnpm 10.29 adds catalog specifier, and includes several bug fixes.","date":"2026-02-07T00:00:00.000Z","tags":[{"inline":true,"label":"release","permalink":"/blog/tags/release"}],"readingTime":2.47,"hasTruncateMarker":true,"authors":[{"name":"Zoltan Kochan","title":"Lead maintainer of pnpm","url":"https://x.com/zkochan","socials":{"x":"https://x.com/zkochan","github":"https://github.com/zkochan"},"imageURL":"https://pbs.twimg.com/profile_images/2005604765028245504/SudRBVMH_400x400.jpg","key":"zkochan","page":null}],"frontMatter":{"title":"pnpm 10.29","authors":"zkochan","tags":["release"],"date":"2026-02-07T00:00:00.000Z"},"unlisted":false,"prevItem":{"title":"pnpm 10.30","permalink":"/blog/releases/10.30"},"nextItem":{"title":"pnpm 10.28","permalink":"/blog/releases/10.28"}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.