logo

pnpm 11.5 Adds Support for Recognizing npm Staged Publishes

ID: c5752bad-fc62-5a24-ae41-94350c270e70

STIX ID: report--c5752bad-fc62-5a24-ae41-94350c270e70

Feed Name: Socket Blog

Threat Score
45/100

Date Published: 2026-06-04

Date Updated: 2026-06-11

Author: Sarah Gooding

...
...

pnpm 11.5 updates trust evaluation to treat npm "staged publishing" approvals (presence of an `approver` field) as the strongest trust signal, fixing false ‘no-downgrade’ warnings when staged publishes were misclassified as a fallback to weaker, token-based publishing. The change responds to prior credential-theft and token-abuse supply-chain incidents (e.g., the Mini Shai-Hulud campaign) and aims to reduce noisy alerts while package managers adapt to npm’s newer trusted- and staged-publishing workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.