pnpm 11 Introduces Default Minimum Release Age to Mitigate Supply Chain Risks
Article Content
- •pnpm 11 introduces a default Minimum Release Age of 24 hours for package versions.
- •The update aims to mitigate risks associated with supply chain attacks in the npm ecosystem.
- •Security-first defaults are now enabled out of the box in pnpm 11.
pnpm 11 has been released on May 5, 2026, implementing a default Minimum Release Age of 24 hours for newly published package versions. This change aims to reduce the risk of supply chain attacks within the npm ecosystem, which has been increasingly targeted by threat actors exploiting public package registries. By delaying the availability of new package versions, pnpm 11 seeks to provide developers with a buffer period to identify and mitigate potential threats. The npm ecosystem has faced numerous incidents where malicious code was injected into packages, making this update a significant step towards enhancing security. The introduction of security-first defaults in pnpm 11 directly addresses these modern package ecosystem threats. Developers using pnpm are now better equipped to protect their environments from supply chain vulnerabilities. The current status of pnpm 11 is that it has been officially released and is available for use.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…