pnpm 11.5 Adds Support for Recognizing npm Staged Publishes
ID: c5752bad-fc62-5a24-ae41-94350c270e70
STIX ID: report--c5752bad-fc62-5a24-ae41-94350c270e70
Feed Name: Socket Blog
pnpm 11.5 updates trust evaluation to treat npm "staged publishing" approvals (presence of an `approver` field) as the strongest trust signal, fixing false ‘no-downgrade’ warnings when staged publishes were misclassified as a fallback to weaker, token-based publishing. The change responds to prior credential-theft and token-abuse supply-chain incidents (e.g., the Mini Shai-Hulud campaign) and aims to reduce noisy alerts while package managers adapt to npm’s newer trusted- and staged-publishing workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
