pnpm
npm
pkg:npm/pnpm
1,364 Dependabot PRs
4 days ago
377 repositories
16 repositories
Security Advisories
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
pnpm vulnerable to Command Injection via environment variable substitution
pnpm has symlink traversal in file:/git dependencies
pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
Recent PRs (filtered by: Patch PRs )
build(deps-dev): Bump pnpm from 11.1.2 to 11.1.3
AtCoder-NoviSteps/AtCoderNoviSteps #3567
chore(deps): bump the minor-and-patch group across 1 directory with 11 updates
zkorum/agora #1020
chore(deps): bump pnpm from 10.33.0 to 10.33.2 in /frontend
CreateIntelligens/arcreel360 #7
chore(deps)(deps-dev): bump the development-deps group with 6 updates
brandonlacoste9-tech/flow-guru-web #10
Bump pnpm from 10.33.0 to 10.33.2
gflohr/e-invoice-eu #558
Bump pnpm from 10.32.0 to 10.32.1 in the npm group
poad/github-pull-requester #2650
Bump the dev-tools group across 1 directory with 10 updates
Bump pnpm from 10.28.0 to 10.28.2 in the npm_and_yarn group across 1 directory
jamilahmedansari/manus-talk-to-my #2
Bump the npm group with 16 updates
poad/github-pull-request-auto-merge-enable-action #9685
chore(deps): bump pnpm from 10.28.0 to 10.28.2
Trancendos/trancendos-ecosystem #492
chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 8 updates
Bump the npm group with 2 updates
poad/github-pull-request-auto-merge-enable-action #9667
chore(deps): bump the minor-and-patch group in /services/shared-app-api with 5 updates
zkorum/agora #592
Bump pnpm from 10.30.0 to 10.30.1 in the sveltekit group
poad/sveltekit-minimal-example #516
chore(deps): bump the minor-and-patch group with 17 updates
chore(deps)(deps): bump the production-dependencies group with 6 updates
chore(deps-dev)(deps-dev): bump the development-dependencies group with 4 updates
skittlz444/walk-to-mordor #243
Bump the packages group with 19 updates
poad/github-rest-api-executor #354
Bump the npm group across 1 directory with 2 updates
poad/aws-cloudformation-stack-status-checker #767
Bump the packages group with 8 updates
poad/github-rest-api-executor #352
Bump the npm group with 5 updates
poad/vercel-functions-example #415
chore(deps): bump the test-versions group across 1 directory with 73 updates
DataDog/dd-trace-js #7462
Bump the npm_and_yarn group across 2 directories with 2 updates
chore(deps-dev): bump the minor-version-updates group across 1 directory with 3 updates
chore(deps): bump the test-versions group across 1 directory with 67 updates
DataDog/dd-trace-js #7417
:arrow_up:(deps): Bump the all-dependencies group with 50 updates
chore(deps): bump the production-dependencies group across 1 directory with 7 updates
chore(deps-dev): bump pnpm from 10.28.0 to 10.28.2
erikvullings/mithril-ui-form #17
Bump pnpm from 10.28.1 to 10.28.2
poad/vercel-functions-example #406
chore(deps): bump pnpm from 10.28.1 to 10.28.2 in the npm_and_yarn group across 1 directory
MisskeyIO/misskey #1416
Bump pnpm from 10.28.1 to 10.28.2
poad/github-pull-requester #2607
build(deps): bump pnpm from 10.28.1 to 10.28.2
sainnhe/dotfiles #11
chore(deps): bump the test-versions group across 1 directory with 55 updates
DataDog/dd-trace-js #7332
chore(deps): bump the npm-minor group in /frontend with 9 updates
0xReLogic/Zeltra #32
Bump the all-dependencies group in /frontend with 8 updates
pkemkes/the-gist-of-it-sec #64
chore(deps): bump the production-dependencies group across 1 directory with 5 updates
Bump the npm group with 2 updates
poad/github-pull-requester #2601
chore(deps): bump the production-dependencies group across 1 directory with 2 updates
chore(deps): bump the production-dependencies group across 1 directory with 3 updates
build(deps-dev): Bump pnpm from 10.28.0 to 10.28.1
AtCoder-NoviSteps/AtCoderNoviSteps #3071
build(deps-dev): Bump pnpm from 10.26.1 to 10.26.2
cynarAI/Houston #122
chore(deps): bump the production-dependencies group across 1 directory with 2 updates
Bump the npm group with 2 updates
poad/github-oauth-example #2051
chore(deps-dev): bump the development-dependencies group across 1 directory with 7 updates
Bump pnpm from 10.26.0 to 10.26.1 in the npm group across 1 directory
poad/aws-cloudformation-stack-status-checker #739
Bump pnpm from 10.26.0 to 10.26.1 in the npm group across 1 directory
poad/get-aws-ssm-parameter #714
Bump the patch-updates group across 1 directory with 14 updates
trtyr/Mizuki #10
build(deps): bump the non-breaking-changes group across 1 directory with 6 updates
esdora-js/esdora #161
Bump the patch-updates group across 1 directory with 5 updates
jianlongliu/jianlongliu.github.io #17
Package Details
| Name: | pnpm |
| Ecosystem: | npm |
| PURL Type: | npm |
| Package URL: | pkg:npm/pnpm |
| JSON API: | View JSON |
Security Advisories
Package Information
Fast, disk space efficient package manager
| Repository: | https://github.com/pnpm/pnpm |
| Homepage: | https://pnpm.io |
| Latest Release: |
10.11.0
about 1 year ago |
| Dependent Repos: | 2,954 |
| Dependent Packages: | 1,314 |
| Downloads: | 88,232,668 |
| Ranking: | Top 0.3962% by dependent repos Top 0.0377% by downloads Top 0.0551% by dependent pkgs |