pnpmjs Profile Banner
pnpm Profile
pnpm

@pnpmjs

Followers
22K
Following
466
Media
203
Statuses
1K

Fast, disk space efficient package manager 快速且節省磁碟空間的套件管理程式 Sponsor us: on GitHub: https://t.co/cS3OP24kZH on OpenCollective: https://t.co/zyVORTsELN

Joined August 2016
Don't wanna be here? Send us removal request.
@pnpmjs
pnpm
2 months
The pnpm repository has 33K stars!
2
2
72
@pnpmjs
pnpm
3 days
The Seattle Times is piloting pnpm’s client-side defenses—blocked lifecycle scripts, release cooldowns, and trust policy—to stop worms like Shai-Hulud 2.0 before they land. Read their story: https://t.co/Vg4C9Qj9q6
Tweet card summary image
pnpm.io
We got lucky with Shai-Hulud 2.0.
1
13
68
@pnpmjs
pnpm
6 days
The npm registry seems to be down
17
23
444
@GOLDCOUNCIL
World Gold Council
1 month
Imagine if everything in life was as good as gold. It’s easy to invest in, could help grow your wealth, and protect it too. A timeless asset that stands strong when others may not.
125
237
4K
@pnpmjs
pnpm
14 days
pnpm v10.24 is out with some performance improvements. https://t.co/0DNx5F4gk1
0
7
104
@pnpmjs
pnpm
16 days
The incidents keep happening. This remains a good idea for pnpm v11 https://t.co/tdjItvkelw
@pnpmjs
pnpm
3 months
Should pnpm delay installation of package versions released less than a day or week ago?
13
2
229
@reinmarpl
Piotrek Koszuliński
17 days
Yet another reminder to use @pnpmjs's minimum dependency age‼️ https://t.co/jg8d7vUoLR
Tweet card summary image
pnpm.io
pnpm gets its configuration from the command line, environment variables, pnpm-workspace.yaml, and
@TheHackersNews
The Hacker News
17 days
🔥 New npm attack DETECTED! A campaign dubbed “Sha1-Hulud: The Second Coming” has compromised hundreds of packages and over 25,000 GitHub repos. The code runs during install, steals cloud logins, and if that fails, it deletes the user’s home folder. Read more ↓
1
5
4
@pnpmjs
pnpm
1 month
Maintaining a CLI app? You can now target only the latest Node.js version — pnpm will install it automatically as a dependency for your app. https://t.co/HO8oUNGq6J
@pnpmjs
pnpm
1 month
🧩 Node.js runtime installation for dependencies pnpm can now automatically install the Node.js version required by a dependency, declared in its engines.runtime field. Example:
3
3
78
@indoorgolfshop
The Indoor Golf Shop ⛳️
28 days
🚨UNEEKOR BLACK FRIDAY SALE - Up to 30% OFF best-selling golf simulators!
2
5
67
@pnpmjs
pnpm
1 month
We have discovered that chokidar has switched off provenance a year ago and now it fails with the trustPolicy setting set to no-downgrade. We'll need to think about a way to deal with these cases. https://t.co/fSEJQYWr1e
@pnpmjs
pnpm
1 month
A new setting, trustPolicy, adds protection against supply-chain attacks. When set to no-downgrade, pnpm will fail installation if a package’s trust level drops — e.g. from a trusted publisher → provenance only → no trust evidence.
4
2
45
@pnpmjs
pnpm
1 month
🎯 In short: Safer installs 🛡️ Smarter runtime management ⚙️ Upgrade to pnpm v10.21: pnpm self-update Full changelog 👉
Tweet card summary image
pnpm.io
Added support for Node.js runtime installation for dependencies and a setting for configuring trust policy.
0
0
11
@pnpmjs
pnpm
1 month
This feature helps detect and block potentially compromised releases, such as when a package’s maintainer changes or its build pipeline loses attestation.
1
0
10
@pnpmjs
pnpm
1 month
A new setting, trustPolicy, adds protection against supply-chain attacks. When set to no-downgrade, pnpm will fail installation if a package’s trust level drops — e.g. from a trusted publisher → provenance only → no trust evidence.
2
9
35
@FannieMae
Fannie Mae
3 months
Lenders can more easily work with state and local agencies to find grants and programs that may help borrowers afford a home thanks to our streamlined resources. Learn how.
6
17
201
@pnpmjs
pnpm
1 month
If a package is a CLI app, pnpm will bind that CLI to the specified Node.js version — so it always runs with the compatible runtime, regardless of what’s installed globally. Even postinstall scripts will be executed with the right Node.js version.
1
0
11
@pnpmjs
pnpm
1 month
🧩 Node.js runtime installation for dependencies pnpm can now automatically install the Node.js version required by a dependency, declared in its engines.runtime field. Example:
2
4
27
@pnpmjs
pnpm
1 month
🚀 pnpm v10.21 is out! This release introduces two powerful new security & compatibility features: 1️⃣ Automatic Node.js runtime installation for dependencies 2️⃣ Configurable trust policy for detecting supply-chain downgrades 🧵👇
1
9
75
@antfu7
Anthony Fu 🦋 @antfu.me
1 month
💖 This Sep & Oct, we have forwarded our Open Collective fund to support @chris_zyyv @webfansplz @bluwyoo @KazariEX_0929 @vida_0905 https://t.co/c0zAHED24w https://t.co/x2Cmytmkfr @pnpmjs @iconify_design Join us to show appreciation for our deps and help them be sustainable!
esm.sh
A fast, smart & global CDN for modern(es2015+) web development.
3
11
99
@pnpmjs
pnpm
1 month
pnpm 10.20 is out. Published via a trusted github action using OIDC.
5
11
475
@VISITFLORIDA
VISIT FLORIDA
1 month
Stir up the group chat with a "let’s go to Florida this weekend 😎”
0
11
209
@ZoltanKochan
Zoltan Kochan
2 months
Surprisingly, none of the package managers are published using OIDC publishing today. Even npm CLI. I did configure OIDC publishing for @pnpmjs, so it will be "trusted" in the next version
1
1
33
@pnpmjs
pnpm
2 months
pnpm v10.19 is out! https://t.co/SR7gxwfalU
0
7
39
@ZoltanKochan
Zoltan Kochan
2 months
I remember using CKEditor at JustAnswer and being really excited when they were considering pnpm years ago. They decided not to switch back then — feels good to win them over at last. https://t.co/vhsCw8tej5
@reinmarpl
Piotrek Koszuliński
2 months
It's impressive to see how quickly @pnpmjs added support for "minimal dependency age" ( https://t.co/3Wl5MDXGBa) after the recent supply chain attacks on npm 😍 By a total coincidence, just a month ago, we finished a migration to pnpm. We definitely don’t look back 🚀 And today,
1
2
11
@pnpmjs
pnpm
2 months
This is nice. We did not have to make any changes on our side to make this work https://t.co/CqNiIRgpNO
@feross
Feross
2 months
Works flawlessly with pnpm!
2
6
31
@weare_unplugged
Unplugged
23 days
For the soldier who needs to go dark; the case officer making the covert drop; and the dissident who can't afford a single trace. But UP Phone isn't just for soldiers and spies; it's for you too. Ordinary people deserve privacy and to own their data.
0
12
100