pnpm
npm
pkg:npm/pnpm
1,356 Dependabot PRs
about 9 hours ago
373 repositories
24 repositories
Security Advisories
pnpm has Windows-specific tarball Path Traversal
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
pnpm has symlink traversal in file:/git dependencies
pnpm vulnerable to Command Injection via environment variable substitution
pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
Recent PRs
chore(deps): bump the test-versions group across 1 directory with 20 updates
DataDog/dd-trace-js #8737
chore(deps-dev)(deps-dev): bump the development-dependencies group with 5 updates
skittlz444/walk-to-mordor #433
chore(deps): bump the test-versions group across 1 directory with 17 updates
DataDog/dd-trace-js #8696
chore(deps): bump the test-versions group across 1 directory with 13 updates
DataDog/dd-trace-js #8650
chore(deps-dev): bump pnpm from 11.1.3 to 11.3.0 in /frontend
chore(deps-dev)(deps-dev): bump pnpm from 10.33.2 to 11.3.0
skittlz444/walk-to-mordor #427
chore(deps-dev): bump pnpm from 11.1.2 to 11.2.2 in /frontend
karimz1/imgcompress #656
Bump the npm_and_yarn group across 9 directories with 19 updates
Surfndez/next.js #15
Bump pnpm from 11.1.3 to 11.2.2
gflohr/pdf-lab #54
build(deps-dev): Bump pnpm from 11.1.2 to 11.1.3
AtCoder-NoviSteps/AtCoderNoviSteps #3567
Bump the all-dependencies group across 1 directory with 38 updates
npm(dev)(deps-dev): bump the development-dependencies group with 7 updates
skittlz444/stonks #135
build(deps): bump the non-breaking-changes group across 1 directory with 11 updates
esdora-js/esdora #214
Bump the npm_and_yarn group across 1 directory with 25 updates
Bump pnpm from 11.0.6 to 11.1.1
mallowlabs/npm-ls-overrides #80
Bump the npm_and_yarn group across 7 directories with 20 updates
Surfndez/next.js #12
Bump the all-dependencies group across 1 directory with 31 updates
chore(deps): bump the minor-and-patch group across 1 directory with 50 updates
Bump the npm_and_yarn group across 1 directory with 15 updates
drzo/bolt.ceo #28
build(deps): bump the non-breaking-changes group with 10 updates
esdora-js/esdora #210
chore(deps): bump pnpm from 10.33.0 to 11.0.9 in /frontend
kiuci/ArcReelVN #29
chore(deps-dev)(deps-dev): bump pnpm from 10.33.2 to 11.0.9
skittlz444/walk-to-mordor #420
chore(deps-dev): bump the dev-deps group across 1 directory with 8 updates
gtmc-dev/gtmc #56
Bump the npm_and_yarn group across 1 directory with 13 updates
protae5544/copy-of-orchestra-coder #1
Bump pnpm from 10.33.4 to 11.0.8
fireknight-coder/Knight-Blog #8
Bump the npm_and_yarn group across 1 directory with 19 updates
6q58j2q4fc-cmd/MoneyMachine #2
chore(deps): bump the minor-and-patch group across 1 directory with 20 updates
mherod/get-cookie #509
chore(deps): bump the minor-and-patch group across 1 directory with 11 updates
zkorum/agora #1020
chore(deps): bump the npm-minor group across 1 directory with 16 updates
0xReLogic/Zeltra #77
build(deps): bump the npm_and_yarn group across 8 directories with 11 updates
QueenFi703/microsoft-365-agents-toolkit #4
chore(deps): bump pnpm from 10.33.0 to 10.33.2 in /frontend
CreateIntelligens/arcreel360 #7
:arrow_up:(deps): Bump the all-dependencies group across 1 directory with 46 updates
StudentTechUsher/stu #162
chore(deps): bump the minor-and-patch group across 1 directory with 42 updates
Rieki777/ReGenCivics.Earth #12
chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 26 updates
chore(deps)(deps-dev): bump the development-deps group with 6 updates
brandonlacoste9-tech/flow-guru-web #10
chore(deps): bump the dev-dependencies group across 1 directory with 12 updates
Bump pnpm from 10.33.0 to 10.33.2
gflohr/e-invoice-eu #558
chore(deps): bump the production-dependencies group across 1 directory with 20 updates
chore(deps): bump the npm-non-major group across 1 directory with 45 updates
Trancendos/trancendos-ecosystem #686
chore(deps): bump the npm_and_yarn group across 2 directories with 5 updates
Bump the npm_and_yarn group across 1 directory with 25 updates
Bump the npm_and_yarn group across 1 directory with 24 updates
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates
chore(deps): bump the npm-non-major group across 1 directory with 38 updates
Trancendos/trancendos-ecosystem #669
Bump the npm_and_yarn group across 1 directory with 22 updates
drzo/bolt-diy-55 #23
Bump the npm_and_yarn group across 1 directory with 21 updates
drzo/bolt.ceo #22
chore(deps): bump the npm-non-major group across 1 directory with 38 updates
Trancendos/trancendos-ecosystem #659
Bump the patch-minor group across 1 directory with 14 updates
Balssh/blog #7
chore(deps): bump the minor-and-patch group across 1 directory with 40 updates
Package Details
| Name: | pnpm |
| Ecosystem: | npm |
| PURL Type: | npm |
| Package URL: | pkg:npm/pnpm |
| JSON API: | View JSON |
Security Advisories
Package Information
Fast, disk space efficient package manager
| Repository: | https://github.com/pnpm/pnpm |
| Homepage: | https://pnpm.io |
| Latest Release: |
10.11.0
about 1 year ago |
| Dependent Repos: | 2,954 |
| Dependent Packages: | 1,314 |
| Downloads: | 88,232,668 |
| Ranking: | Top 0.3962% by dependent repos Top 0.0377% by downloads Top 0.0551% by dependent pkgs |