pnpm 11 Targets npm Supply Chain Threats With Minimum Release Age Safeguard
ID: fa2a54b1-fdc9-5a9e-9f9b-7bcba267e3df
STIX ID: report--fa2a54b1-fdc9-5a9e-9f9b-7bcba267e3df
Feed Name: Cyber Press
pnpm 11 introduces default supply-chain protections—such as a 24-hour minimum release age, blocking of non-registry (exotic) transitive dependencies, and a controlled Allow Builds model—to mitigate fast-moving package compromise campaigns like the reported “Mini Shai-Hulud” attacks that used preinstall hooks to deploy credential stealers across npm, PyPI, and Packagist. The release also modernizes performance and vulnerability-management features (SBOM generation, GHSA-based auditing, SQLite store index) and previews a Rust-based installer (Pacquet) for future speed and reliability gains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
