🚀Performance improvement: Use reflinks instead of hard links by default on macOS and Windows Dev Drives #5001.
The list of packages that are allowed to run installation scripts now may be provided in a separate configuration file. The path to the file should be specified via the pnpm.onlyBuiltDependenciesFile field in package.json. For instance:
Add disallow-workspace-cycles option to error instead of warn about cyclic dependencies
Allow env rm to remove multiple node versions at once, and introduce env add for installing node versions without setting as default #7155.
Patch Changes
Fix memory error in pnpm why when the dependencies tree is too big, the command will now prune the tree to just 10 end leafs and now supports --depth argument #7122.
Use neverBuiltDependencies and onlyBuiltDependencies from the root package.json of the workspace, when shared-workspace-lockfile is set to false #7141.
Optimize peers resolution to avoid out-of-memory exceptions in some rare cases, when there are too many circular dependencies and peer dependencies #7149.
Instead of pnpm.overrides replacing resolutions, the two are now merged. This is intended to make it easier to migrate from Yarn by allowing one to keep using resolutions for Yarn, but adding additional changes just for pnpm using pnpm.overrides.
Add --reporter-hide-prefix option for run command to hide project name as prefix for lifecycle log outputs of running scripts #7061.
Patch Changes
Pass through the --ignore-scripts command to install, when running pnpm dedupe --ignore-scripts #7102.
Throw meaningful error for config sub commands#7106.
When the node-linker is set to hoisted, the package.json files of the existing dependencies inside node_modules will be checked to verify their actual versions. The data in the node_modules/.modules.yaml and node_modules/.pnpm/lock.yaml may not be fully reliable, as an installation may fail after changes to dependencies were made but before those state files were updated #7107.
Don't update git-hosted dependencies when adding an unrelated dependency #7008.
Don't run the prepublishOnly scripts of git-hosted dependencies #7026.
Fix a bug in which use-node-version or node-version isn't passed down to checkEngine when using pnpm workspace, resulting in an error #6981.
Don't print out each deprecated subdependency separately with its deprecation message. Just print out a summary of all the deprecated subdependencies #6707.
Fixed an ENOENT error that was sometimes happening during install with "hoisted" node_modules #6756.
Improve performance of installation by using a worker for creating the symlinks inside node_modules/.pnpm #7069.
Tarballs that have hard links are now unpacked successfully. This fixes a regression introduced in v8.7.0, which was shipped with our new in-house tarball parser #7062.
Fix a bug causing errors to be printed as "Cannot read properties of undefined (reading 'code')" instead of the underlying reason when using the pnpm store server #7032
Fixed an issue with extracting some old versions of tarballs #6991.
Side-effects cache will now be leveraged when running install in a workspace that uses dedicated lockfiles for each project #6890.
Reduce concurrency in the pnpm -r publish command #6968.
Improved the pnpm update --interactive output by grouping dependencies by type. Additionally, a new column has been added with links to the documentation for outdated packages #6978.
Improve performance of installation by using a worker pool for extracting packages and writing them to the content-addressable store #6850
The default value of the resolution-mode setting is changed to highest. This setting was changed to lowest-direct in v8.0.0 and some users were not happy with the change. A twitter poll concluded that most of the users want the old behaviour (resolution-mode set to highest by default). This is a semi-breaking change but should not affect users that commit their lockfile #6463.
Patch Changes
Warn when linking a package with peerDependencies #615.
Add support for npm lockfile v3 in pnpm import #6233.
Override peerDependencies in pnpm.overrides #6759.
Respect workspace alias syntax in pkg graph #6922
Emit a clear error message when users attempt to specify an undownloadable node version #6916.
pnpm patch should write patch files with a trailing newline #6905.
Dedupe deps with the same alias in direct dependencies 6966
Don't prefix install output for the dlx command.
Performance optimizations. Package tarballs are now download directly to memory and built to an ArrayBuffer. Hashing and other operations are avoided until the stream has been fully received #6819.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
Release Notes
pnpm/pnpm (pnpm)v8.9.2
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.9.1
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.9.0
Compare Source
Minor Changes
🚀Performance improvement: Use reflinks instead of hard links by default on macOS and Windows Dev Drives #5001.
The list of packages that are allowed to run installation scripts now may be provided in a separate configuration file. The path to the file should be specified via the pnpm.onlyBuiltDependenciesFile field in package.json. For instance:
{ "dependencies": { "@​my-org/policy": "1.0.0" } "pnpm": { "onlyBuiltDependenciesFile": "node_modules/@​my-org/policy/allow-build.json" } }In the example above, the list is loaded from a dependency. The JSON file with the list should contain an array of package names. For instance:
With the above list, only esbuild and @reflink/reflink will be allowed to run scripts during installation.
Related issue: #7137.
Add disallow-workspace-cycles option to error instead of warn about cyclic dependencies
Allow env rm to remove multiple node versions at once, and introduce env add for installing node versions without setting as default #7155.
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.8.0
Compare Source
Minor Changes
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.7.6
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.7.5
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.7.4
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.7.3
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.7.2
Compare Source
v8.7.1
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.7.0
Compare Source
Minor Changes
Patch Changes
Our Gold Sponsors
Our Silver Sponsors
v8.6.12
Compare Source
Patch Changes
Our Gold Sponsors
Our Silver Sponsors