Release Notes
Minor Changes
Added a new setting,
update.githubActionsServer, for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files (for example, a GitHub Enterprise Server). When the setting is not defined, the URL is read from theGITHUB_SERVER_URLenvironment variable, falling back tohttps://github.com. The URL must use thehttps://orhttp://protocol #13220.pnpm outdatedandpnpm updateno longer fail when the refs of a GitHub Action's repository cannot be read (for example, when the action's repository is private or hosted on a different GitHub server). Such actions are now skipped with a warning.Setting
update.githubActionstofalsenow makespnpm outdatedand the interactivepnpm updateskip GitHub Actions dependencies.Added the
pnpm unpublishcommand: remove a package from the registry entirely (requires--force), or remove the versions matching<package>@<range>, re-pointingdist-tagsthat referenced them and deleting the orphaned tarballs. Supports--registryand--otp.
Patch Changes
The token poll for web-based authentication no longer reads the body of non-OK or still-pending (HTTP 202) responses, and caps the token response body it does read at 64 KiB, so a malicious or compromised registry cannot exhaust memory through the poll pnpm/pnpm#12721.
pnpm install --no-runtimenow works without--frozen-lockfile: on a fresh install, runtime dependencies are resolved and recorded in the lockfile, but their archives are not downloaded and their bins are not linked.pnpm outdatednow aligns its table borders when the output is colorized. The color escape codes in thePackageandLatestcells were being counted as visible characters, so the columns and box-drawing borders drifted out of alignment on a terminal.pnpm packandpnpm publishno longer let workspace-root.gitignore/.npmignorerules exclude files matched by the package manifest'sfilesallowlist. Workspace packages whose build output is gitignored at the workspace root (for example a compiledlib/directory listed infiles) were published with almost all payload files missing #13164.Fixed
pnpm update --latestfailing withERR_PNPM_PACKAGE_MANAGER_UPDATE_RESOLVE_LATESTwhen a dependency uses theworkspace:(orlink:/file:) protocol. Such a dependency links a local package that may not be published, so there is no registry "latest" to resolve — it is now skipped and preserved verbatim, matching the TypeScript CLI. Previously onlyworkspace:<path>specifiers were skipped, soworkspace:*/workspace:^1.0.0deps pointing at unpublished packages made--latesttry to fetch them from the registry and 404.pnpm viewnow accepts the--registryoption, matching the TypeScript CLI. Previously the flag was rejected as an unknown argument.When the authentication URL cannot be rendered as a QR code (for example when it exceeds the maximum QR data capacity), web-based login now displays the URL alone with a warning instead of aborting authentication pnpm/pnpm#12721.