#pnpm

Orhun Parmaksız 👾orhun@fosstodon.org
2026-01-30

Wow this is perfect for keeping NPM dependencies secure 🔥

👮 **deputui** — A TUI for reviewing release notes of your NPM dependencies

💯 Pipe in pnpm outdated, skim release notes and select exactly which updates to install

🦀 Written in Rust & built with @ratatui_rs

⭐ GitHub: github.com/twiddler/deputui

#rustlang #ratatui #tui #npm #pnpm #security #packaging #dependencies

Zafir SK Heerahzfir
2026-01-29

Speeding up Docker builds with pnpm store caching 🚀

If your containers keep re-downloading dependencies, you’re losing a lot of time. pnpm uses a global store—so persisting it with a named Docker volume makes pnpm install much faster after the first run.

Short guide: l.zfir.dev/9MFJSUo

2026-01-10
2026-01-06

Why not go whole hog? While not have wrapper / generic methods for actions, like "install <package>".

That way you can define what package manager you're using, without needing to know specifics. And swapping between them would be easy.
The more advanced stuff could then be handled if / when it was required 🤔

This has drawbacks, and complexities, but at the moment I'm really not getting what's special or valuable about Corepack.

#webdev #code #tech #node #javascript #npm #yarn #pnpm

2026-01-06

The GitHub docs state:

> In practical terms, **Corepack lets you use Yarn, npm, and pnpm without having to install them**.

But... it looks like Corepack just downloads and installs them *for you*. At least it's the right version / hash checked.

I feel like I'm missing something here...

#webdev #code #tech #node #javascript #npm #yarn #pnpm

2026-01-05

`pnpm` is lockfile compatible!? I can just type this in every project instead of remembering #npm #yarn #pnpm #bun #etc!?

2025-12-31
2025-12-29

npm đang xem xét thêm tính năng "minimumReleaseAge" tương tự pnpm và yarn, giúp giới hạn thời gian cập nhật version mới của dependency, tránh rủi ro lỗi. #npm #pnpm #yarn #QuanLyPhiênBản #TechViet

reddit.com/r/programming/comme

2025-12-16
codeDude :archlinux: :neovim:codeDude@floss.social
2025-12-16

Today I started to collaborate with the #mastodon project and to build the project I learn something named #corepack that it is a manager for #nodejs package manager hahahaha. Today I learn something new
#javascript #nodejs #npm #yarn #pnpm

2025-12-10

Cool write up from #SeattleTimes about using #pnpm to suppress #npm lifecycle scripts: pnpm.io/blog/2025/12/05/newsro

Nothing like realizing you’ve been just executing arbitrary scripts from the internet for years. 😬

#javascript #security

2025-12-08
2025-12-07

How We're Protecting Our Newsroom from npm Supply Chain Attacks

mander.xyz/post/43195694

Tadashi Shigeokacodenote
2025-12-05

🔒 Quick tip for users:

Use `minimumReleaseAge` for stability, but need an emergency security update?

`minimumReleaseAgeExclude` lets you bypass the wait for specific packages without disabling your safety net.

Real-world example from our React CVE response 👇
codenote.net/en/posts/pnpm-min

sb arms & legssb@metroholografix.ca
2025-11-29

Meanwhile, I'm just trying to update an application on my server, but I need a specific version of #pnpm :(

2025-11-27
lil5 🚲 🇳🇱lil5@social.linux.pizza
2025-11-27

This is exactly what #opensourcesecuritypodcast talked about in:

opensourcesecurity.io/2025/202

And I just found one in the wild. How?: by using #pnpm (instead of npm) and taking the short time to read the postinstall script. Not rocket science.

lil5 🚲 🇳🇱lil5@social.linux.pizza
2025-11-24

@dolanor

TLDR start using pnpm.

They have those scripts turned off by default.

#npm #pnpm #javascript

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst