Back to Daily Feed 
pnpm 11.9 Enhances Package Integrity and SBOM Generation
Worth Reading
Originally published on pnpm Releases
View Original Article
Share this article:
Summary & Key Takeaways
- pnpm now computes and stores integrity checksums for tarballs from registries that don't provide them initially.
- This ensures verifiability for all lockfile entries on subsequent installs.
- A new
--exclude-peersflag has been added topnpm sbomfor more accurate Software Bill of Materials. - The
pnpm audit --fixnow consolidatesminimumReleaseAgeExcludeentries for better readability. - Non-deterministic peer resolution issues, particularly with optional transitive peers, have been addressed.
Our Commentary
This pnpm update is a solid win for reliability and security. The automatic integrity checksums are a big deal for ensuring consistent builds, especially with those tricky on-demand registries. And the SBOM improvements? Crucial for supply chain security. We're seeing more and more focus on these foundational aspects of tooling, and I'm here for it. It's the kind of work that often goes unnoticed but prevents major headaches down the line.
View Original Article
Share this article: