pnpm 12.12.0
This release shares task results and dependency builds through a remote cache, adds the addMissingPeerTypes setting, and lets pnpm add --config and pnpm update manage configuration dependencies. It also fixes dangerouslyAllowAllBuilds running the build scripts of packages that allowBuilds denies.
Minor Changes#
-
pnpm pipelinecan share task results between machines. A result is a signed artifact stored on a pnpr server or on a server that speaks the Turborepo Remote Cache API, such as Vercel Remote Cache.The remote side-effects cache can also store dependency builds on a Turborepo Remote Cache server. Both caches read the new
remoteCachesetting, which names the server and holds the signing keys.pnpm pipeline --reportrecords the run under the organizationremoteCache.orgnames. -
Added the
addMissingPeerTypessetting, which links the@typespackage of a peer dependency next to every package that peer-depends on it. For example, a package that peer-depends onreactgets the project's@types/reactlinked next to it. This lets TypeScript find the types of a peer dependency when the global virtual store is on #15689. -
pnpm add --configandpnpm updatenow handle configuration dependencies the way they handle other dependencies #16814.pnpm add --configsaves a version range inpnpm-workspace.yamlby the same rules aspnpm add, sopnpm add --config my-config@latestsaves a range such as^1.2.0. It also resolves the package again whenpnpm-lock.yamlalready locks an older version.pnpm updateupdates configuration dependencies within their ranges, andpnpm update --latestmoves them to their latest version. A selector such aspnpm update my-configupdates only the configuration dependencies it names.
Patch Changes#
-
A package set to
falseinallowBuildsno longer runs its build scripts whendangerouslyAllowAllBuildsistrue. The two settings together now allow every build except the denied ones. Previously,dangerouslyAllowAllBuildsignored the denials. -
pnpm now switches to the pnpm version a project pins even when it cannot read its configuration. Previously, a setting it rejected in the global config file, an
.npmrcfile, or_auth, or apnpm-workspace.yamlit could not parse, stopped every command,pnpm --versionincluded. -
pnpm updateandpnpm whyaccept--depth Infinityagain. They failed withinvalid value 'Infinity' for '--depth <DEPTH>'#16817. -
pnpm deploywithoutinjectWorkspacePackagesnow binds a peer dependency of a linked workspace package to the version its parent provides, as an injected install does. Previously the deploy failed withERR_PNPM_DEPLOY_AMBIGUOUS_PEERwhenever other packages in the deployed graph depended on different versions of that peer #16807. -
pnpm deploy --legacyno longer fails withERR_PNPM_SPEC_NOT_SUPPORTED_BY_ANY_RESOLVERwhen a workspace dependency of the deployed project declares aworkspace:peer dependency that the project does not depend on itself. pnpm now copies that peer from the workspace into the deploy directory.An auto-installed peer declared with
workspace:now always resolves to the workspace project. Previously,workspace:*andworkspace:^1.0.0peers could be installed from the registry #16806. -
Repeat installs no longer resolve again when an injected workspace package lists a dependency also as a peer dependency.
-
Sped up frozen installs of unchanged injected workspace packages that use hardlinks.
-
Sped up workspace discovery with subtree exclusions such as
!generated/**. -
A key under a registry URL in the
_authsetting that does not start with@is now skipped with a warning, so a field a later pnpm version adds there no longer breaks this one. A key that holds anauthTokenobject but lacks its@, such asorgfor@org, is still an error.