PageSourceSearch

https://pnpm.io/assets/js/8ad4685a.0cb023b2.js

js pnpm.io collected 2026-09-24 07:25:04 UTC 7,275 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk=self.webpackChunk||[]).push([["35751"],{80796(e,t,i){i.r(t),i.d(t,{metadata:()=>s,default:()=>p,frontMatter:()=>r,contentTitle:()=>a,toc:()=>c,assets:()=>l});var s=JSON.parse('{"id":"supply-chain-security","title":"Mitigating supply chain attacks","description":"Sometimes npm packages are compromised and published with malware. Luckily, there are companies like [Socket], [Snyk], and [Aikido] that detect these compromised packages early. The npm registry usually removes the affected versions within hours. However, there is always a window of time between when the malware is published and when it is detected, during which you could be exposed. Fortunately, there are some things you can do with pnpm to minimize the risks.","source":"@site/versioned_docs/version-10.x/supply-chain-security.md","sourceDirName":".","slug":"/supply-chain-security","permalink":"/10.x/supply-chain-security","draft":false,"unlisted":false,"editUrl":"https://github.com/pnpm/pnpm.io/edit/main/versioned_docs/version-10.x/supply-chain-security.md","tags":[],"version":"10.x","lastUpdatedBy":"Zoltan Kochan","lastUpdatedAt":1771892155000,"frontMatter":{"id":"supply-chain-security","title":"Mitigating supply chain attacks"},"sidebar":"docs","previous":{"title":"Continuous Integration","permalink":"/10.x/continuous-integration"},"next":{"title":"Working with TypeScript","permalink":"/10.x/typescript"}}'),n=i(91987),o=i(67008);let r={id:"supply-chain-security",title:"Mitigating supply chain attacks"},a,l={},c=[{value:"Block risky postinstall scripts",id:"block-risky-postinstall-scripts",level:3},{value:"Prevent exotic transitive dependencies",id:"prevent-exotic-transitive-dependencies",level:3},{value:"Delay dependency updates",id:"delay-dependency-updates",level:3},{value:"Enforce trust with trustPolicy",id:"enforce-trust-with-trustpolicy",level:3},{value:"Use a lockfile",id:"use-a-lockfile",level:3}];function d(e){let t={a:"a",code:"code",h3:"h3",p:"p",...(0,o.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsxs)(t.p,{children:["Sometimes npm packages are compromised and published with malware. Luckily, there are companies like ",(0,n.jsx)(t.a,{href:"https://socket.dev/",children:"Socket"}),", ",(0,n.jsx)(t.a,{href:"https://snyk.io",children:"Snyk"}),", and ",(0,n.jsx)(t.a,{href:"https://www.aikido.dev/",children:"Aikido"})," that detect these compromised packages early. The npm registry usually removes the affected versions within hours. However, there is always a window of time between when the malware is published and when it is detected, during which you could be exposed. Fortunately, there are some things you can do with pnpm to minimize the risks."]}),"\n",(0,n.jsx)(t.h3,{id:"block-risky-postinstall-scripts",children:"Block risky postinstall scripts"}),"\n",(0,n.jsxs)(t.p,{children:["Historically, most compromised packages have used ",(0,n.jsx)(t.code,{children:"postinstall"})," scripts to run code immediately upon installation. To mitigate this, pnpm v10 disables the automatic execution of ",(0,n.jsx)(t.code,{children:"postinstall"})," scripts in dependencies. Although there is a setting to re-enable them globally using ",(0,n.jsx)(t.a,{href:"/10.x/settings#dangerouslyallowallbuilds",children:"dangerouslyAllowAllBuilds"}),", we recommend explicitly listing only trusted dependencies using ",(0,n.jsx)(t.a,{href:"/10.x/settings#allowbuilds",children:"allowBuilds"}),". This way, if a dependency did not require a build in the past, it won't suddenly run a malicious script if a compromised version is published. Still, we recommend being cautious when updating a trusted package that has a ",(0,n.jsx)(t.code,{children:"postinstall"})," script, as ",(0,n.jsx)(t.a,{href:"https://socket.dev/blog/nx-packages-compromised",children:"it might get compromised"}),"."]}),"\n",(0,n.jsx)(t.h3,{id:"prevent-exotic-transitive-dependencies",children:"Prevent exotic transitive dependencies"}),"\n",(0,n.jsxs)(t.p,{children:["You can prevent transitive dependencies from using exotic sources (like git repositories or direct tarball URLs) by setting ",(0,n.jsx)(t.a,{href:"/10.x/settings#blockexoticsubdeps",children:"blockExoticSubdeps"})," to ",(0,n.jsx)(t.code,{children:"true"}),". This ensures that all transitive dependencies are resolved from trusted sources, reducing the risk of supply chain attacks."]}),"\n",(0,n.jsx)(t.h3,{id:"delay-dependency-updates",children:"Delay dependency updates"}),"\n",(0,n.jsxs)(t.p,{children:["Another way to reduce the risk of installing compromised packages is to delay updates to your dependencies. Since malware is usually detected quickly, delaying updates by 24 hours will most likely prevent you from installing a bad version. The ",(0,n.jsx)(t.a,{href:"/10.x/settings#minimumreleaseage",children:"minimumReleaseAge"})," setting defines the minimum number of minutes that must pass after a version is published before pnpm will install it. For example, set it to ",(0,n.jsx)(t.code,{children:"1440"})," to wait one day, or ",(0,n.jsx)(t.code,{children:"10080"})," to wait one week before installing a new version."]}),"\n",(0,n.jsx)(t.h3,{id:"enforce-trust-with-trustpolicy",children:"Enforce trust with trustPolicy"}),"\n",(0,n.jsxs)(t.p,{children:["To further protect your supply chain, pnpm also supports a ",(0,n.jsx)(t.a,{href:"/10.x/settings#trustpolicy",children:"trustPolicy"})," setting. When set to ",(0,n.jsx)(t.code,{children:"no-downgrade"}),", this setting will prevent installation of a package if its trust level has decreased compared to previous releases (for example, if it was previously published by a trusted publisher but now only has provenance or no trust evidence). This helps you avoid installing potentially compromised or less trustworthy versions."]}),"\n",(0,n.jsxs)(t.p,{children:["If you need to allow specific packages or versions to bypass the trust policy check, you can use the ",(0,n.jsx)(t.a,{href:"/10.x/settings#trustpolicyexclude",children:"trustPolicyExclude"})," setting. This is useful for known packages that may not meet the trust requirements but are still safe to use."]}),"\n",(0,n.jsxs)(t.p,{children:["Additionally, the ",(0,n.jsx)(t.a,{href:"/10.x/settings#trustpolicyignoreafter",children:"trustPolicyIgnoreAfter"})," setting allows you to ignore trust checks for packages published more than a specified time ago. This is helpful for older versions of packages that lack a process for publishing with signatures or provenance."]}),"\n",(0,n.jsx)(t.h3,{id:"use-a-lockfile",children:"Use a lockfile"}),"\n",(0,n.jsx)(t.p,{children:"It goes without saying that you should always lock your dependencies with a lockfile. Commit your lockfile to your repository to avoid unexpected updates."})]})}function p(e={}){let{wrapper:t}={...(0,o.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(d,{...e})}):d(e)}},67008(e,t,i){i.d(t,{R:()=>r,x:()=>a});var s=i(71763);let n={},o=s.createContext(n);function r(e){let t=s.useContext(o);return s.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:r(e.components),s.createElement(o.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.