pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk
ID: 464a9808-e57b-5c79-9cb0-31f3e39ed47c
STIX ID: report--464a9808-e57b-5c79-9cb0-31f3e39ed47c
Feed Name: cybersecurityNews.com
The article describes pnpm 11's security-by-default changes to reduce npm supply-chain risks: a 24-hour minimumReleaseAge that delays resolution of newly published package versions, default blocking of exotic transitive dependencies, and a new allowBuilds model to limit install-time build script execution. These defaults aim to close the high-risk window when freshly published malicious packages and installer-time hooks can be pulled into developer and CI/CD environments, while allowing teams to override settings for emergency fixes or intentional exotic sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
