chore(deps): update dependency pnpm to v11.28.3 - #1578
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/pnpm-11.x
branch
from
October 3, 2026 16:18
5d75135 to
d937005
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
11.28.2→11.28.311.28.2→11.28.3Release Notes
pnpm/pnpm (pnpm)
v11.28.3: pnpm 11.28.3Compare Source
pnpm 11.28.3 updates
undicito clear a security advisory, fixes "database disk image is malformed" errors when several pnpm processes share a store, and makes packages, catalogs, projects, and commands named likeconstructorwork.Patch Changes
Installing packages
pnpm now ships
undici7.29.1, so security scans of pnpm no longer report GHSA-3wwx-pv8p-q78v.pnpm no longer fails with "database disk image is malformed" or reads stale store entries while another pnpm process writes to the same store.
Names that match built-in JavaScript object properties, such as
constructor,toString, or__proto__, now work like any other name. pnpm crashed, wrote a wrong lockfile, or silently skipped such names in:pnpm add,pnpm install, andpnpm import, for dependencies, peer dependencies, andfile:dependencies that point to a directory namedconstructor.toStringwas not written.$toString.pnpm list, andpnpm why.pnpm constructorruns theconstructorscript like any other unknown command, andpnpm help constructorno longer crashes.constructor.pnpm installno longer re-resolves an up-to-date lockfile on every run when a patched package is a peer in a peer cycle #16418.POSIX bin shims and the
pnpm,pn,pnpx, andpnxlaunchers now run inside a Nix build, where the system default path holds none of the utilities they call. Installing again replaces the shims already innode_modules#16377.In a project that pins another pnpm version, pnpm now passes a command with an option it does not know to the pinned version. Before,
pnpm install --auto-dedupefailed with "Unknown option" even though the pinned pnpm supports it #16353.pnpm now fails with
ERR_PNPM_INVALID_ALLOW_BUILDSwhenallowBuildsis not an object or one of its values is nottrue,false, or a string. Such values used to be ignored silently.Removing a dependency whose bins are declared through
directories.binno longer leaves broken shims innode_modules/.bin.A custom resolver's
shouldRefreshResolutionhook that rejects no longer crashes pnpm with an unhandled rejection when another hook has already asked for a refresh.Updating dependencies
When
minimumReleaseAgehides the version thatlatestpoints to, pnpm now falls back to a prerelease of the same major before a stable version of an older major. A stable version of the same major is still preferred. For example, while a new1.0.0is too new, pnpm picks1.0.0-beta.4rather than an old0.0.1#16388.pnpm --filter <project> update <pkg>now fails withERR_PNPM_NO_PACKAGE_IN_DEPENDENCIESwhen the selected projects do not depend on<pkg>, also in a workspace with a shared lockfile and a root project. It used to exit successfully.pnpm audit --fixnow updates vulnerable packages in a single project that setsupdateConfig.ignoreDependencies. It used to leave them on the vulnerable version.pnpm update --globalnow removes hard-linked executables fromPNPM_HOMEwhen migrating packages from the old global layout #16420.Updating a pinned GitHub Action now rewrites the version in its
# vX.Y.Zcomment even when the action name contains the same version text. The action name used to change while the comment kept the old version.Workspaces and deploy
pnpm deployno longer fails withERR_PNPM_DEPLOY_AMBIGUOUS_PEERin a workspace withinjectWorkspacePackages: truewhen a workspace package also lists its peer dependency as a dev dependency #16375.pnpm deployno longer copies the workspace root'spackageManageranddevEngines.packageManagerfields into the deployedpackage.json#16403.--filterfixes:...pkg...selector combined with another dependents selector, such as--filter ...a --filter ...b..., no longer adds the dependencies of the other selector's dependents.--filter "[<since>]"now detects changes in projects whose directory names contain non-ASCII characters. The change used to be credited to the parent project.Running scripts
After relaying a signal to a script, pnpm keeps waiting for a process in the script's process group whose main thread has exited while its other threads still run. Linux reports such a process as a zombie, so the wait used to end before those threads finished pnpm/tasks#56.
A lifecycle script run with
unsafePerm: falsenow fails with an error when pnpm cannot createnode_modules/.tmp. It used to hang.pnpm runwithverifyDepsBeforeRunno longer crashes with an unhandled rejection when a lockfile it did not need to compare fails to load.pnpm run -rnow closes the collapsible CI log section of a project whose script fails, so the output of later projects is no longer nested inside it.pnpm run --resume-fromno longer crashes when a saved run state file containsnull.Store
pnpm store prunenow removes the packages that only expiredpnpm dlxcache entries used, as long as the store still has another registered project. They used to stay until the nextpnpm store prune#16383.pnpm store prunenow stops with an error when it cannot read a project directory for a reason other than the directory missing, such as a permission error. It used to skip the directory.Publishing and registry output
pnpm publishnow includes bareREADMEfiles and README files with Markdown extensions such asreadme.markdownin registry metadata #12704.pnpm pack-appnow accepts an entry file or output directory inside the project whose name starts with two dots, such as..build/entry.cjs. It used to fail withERR_PNPM_PACK_APP_ENTRY_OUTSIDE_PROJECT.Registry error messages now always say "(response body truncated)" when pnpm cut the response body short. The marker was missing when the body was cut at exactly 64 KiB.
Platinum Sponsors
Gold Sponsors
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.