pnpm
Version: 10.34.1Fast, disk space efficient package manager
What is pnpm?
Fast, disk space efficient package manager
How to use this package
Quick install
Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.
min add pnpm Declare as a task dependency in minimal.toml
Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.
[tasks.dev]
packages = ["pnpm"] Build-time vs runtime
Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.
min add --build pnpm
min add --runtime pnpm Showing 9 advisories, 7 of which are transitive via pnpm's dependencies
No advisories match the current filters.
| Status | IDs | Package | Severity | |||
|---|---|---|---|---|---|---|
| Critical ( 0 ) | ||||||
| High ( 8 ) | ||||||
| Affected: 10.34.1 | pnpm | High: 7.5 | ||||
SummaryCAND-PNPM-123: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle Affected ranges
CVSS vector:
| ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 8.4 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
| ||||||
| Affected: 3.6.2 | openssl | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References
| ||||||
| Resolved in v1.48.0 | libuv | High: 7.3 | ||||
SummaryImproper Domain Lookup that potentially leads to SSRF attacks in libuv Affected ranges
Fixed in:
CVSS vector:
References
| ||||||
| Resolved in 7.9.0* | node-lts | High: 7.5 | ||||
Summarynpm packing does not respect root-level ignore files in workspaces Via: node-lts Affected ranges
Fixed in:
CVSS vector:
References
| ||||||
| Resolved in 0df65d82dbc41e8da00adb243de5918db532c8a6 | openssl | High | ||||
SummaryHeap-buffer-overflow in asn1_ex_i2c Affected ranges
Fixed in:
References | ||||||
| Medium ( 1 ) | ||||||
| Affected: 10.34.1 | pnpm | Medium: 6.5 | ||||
SummaryCAND-PNPM-122: Repository config can expand victim environment secrets into registry requests before scripts run Affected ranges
CVSS vector:
| ||||||
| Low ( 0 ) | ||||||
| Unknown ( 0 ) | ||||||
63 components
No components match your filter.
| Packages | Version |
|---|---|
| pnpm ROOT | 10.34.1 |
| acl | 2.3.2 |
| attr | 2.5.2 |
| autoconf | 2.73 |
| automake | 1.18.1 |
| bash | 5.3 |
| bash-bootstrap | 5.3 |
| binutils | 2.46.1 |
| bison | 3.8.2 |
| bzip2 | 1.0.8 |
| c-ares | 1.34.6 |
| cmake | 4.2.3 |
| coreutils | 9.11 |
| curl | 8.20.0 |
| diffutils | 3.12 |
| expat | 2.7.5 |
| file | 5.47 |
| findutils | 4.10.0 |
| flex | 2.6.4 |
| gawk | 5.4.0 |
| gawk-bootstrap | 5.3.2 |
| gcc | 15.2.0 |
| gdbm | 1.26 |
| glibc | 2.42 |
| gmp | 6.3.0 |
| grep | 3.12 |
| gtest | 1.17.0 |
| gzip | 1.14 |
| icu | 78.3 |
| libcap | 2.78 |
| libffi | 3.5.2 |
| libidn2 | 2.3.8 |
| libpsl | 0.21.5 |
| libtool | 2.5.4 |
| libunistring | 1.4.1 |
| libuv | 1.52.1 |
| linux_headers | 6.12.43 |
| lz4 | 1.10.0 |
| m4 | 1.4.21 |
| make | 4.4.1 |
| meson | 1.10.1 |
| mpc | 1.4.0 |
| mpfr | 4.2.2 |
| ncurses | 6.5-20250830 |
| nghttp2 | 1.68.1 |
| nghttp3 | 1.15.0 |
| ngtcp2 | 1.22.1 |
| ninja | 1.13.2 |
| node-lts | 24.14.1 |
| openssl | 3.6.2 |
| pcre2 | 10.47 |
| perl | 5.42.0 |
| pkgconf | 2.5.1 |
| python | 3.14.5 |
| readline | 8.3 |
| sed | 4.9 |
| setuptools | 82.0.1 |
| sqlite | 3.50.4 |
| tar | 1.35 |
| util-linux | 2.42.1 |
| xz | 5.8.3 |
| zlib | 1.3.2 |
| zstd | 1.5.7 |