Works on dependency management at bit.dev
This release introduces two powerful new security & compatibility features:
1️⃣ Automatic Node.js runtime installation for dependencies
2️⃣ Configurable trust policy for detecting supply-chain downgrades
🧵👇
This release introduces two powerful new security & compatibility features:
1️⃣ Automatic Node.js runtime installation for dependencies
2️⃣ Configurable trust policy for detecting supply-chain downgrades
🧵👇
@kochan.io @pnpm.io
pnpm.io/blog/release...
#ECMAScript #JavaScript
@kochan.io @pnpm.io
pnpm.io/blog/release...
#ECMAScript #JavaScript
It allows you to prevent installing potentially malicious dependency updates that are not signed like previous versions.
pnpm.io/blog/release...
Thank you for all the performance, productivity and security enhancements over the last years 💜
It allows you to prevent installing potentially malicious dependency updates that are not signed like previous versions.
pnpm.io/blog/release...
Thank you for all the performance, productivity and security enhancements over the last years 💜
@kochan.io
softwareengineeringdaily.com/2025/09/18/p...
@kochan.io
softwareengineeringdaily.com/2025/09/18/p...
Tools like Taze and npm-check-updates are testing similar “maturity” options, hinting at a cautious new trend in #JavaScript package management.
socket.dev/blog/pnpm-10... #NodeJS
Tools like Taze and npm-check-updates are testing similar “maturity” options, hinting at a cautious new trend in #JavaScript package management.
socket.dev/blog/pnpm-10... #NodeJS
but "pnix" doesn't sound appropriate 😂
but "pnix" doesn't sound appropriate 😂
bsky.app/profile/pnpm...
pnpm.io/blog/release...
bsky.app/profile/pnpm...
Hope AI: Architect agent that builds professional software
www.producthunt.com/products/hop...
Hope AI: Architect agent that builds professional software
www.producthunt.com/products/hop...
I fixed this locally in 5 mins thanks to the amazing patch ability of @pnpm.io (kudos @kochan.io!) and the LLMs era of code editors
I fixed this locally in 5 mins thanks to the amazing patch ability of @pnpm.io (kudos @kochan.io!) and the LLMs era of code editors
github.com/pnpm/trusted...
github.com/pnpm/trusted...
This is a hook that removes polyfills from dependencies if they are not needed.
This is a hook that removes polyfills from dependencies if they are not needed.