What pnpm/pnpm shipped
Written by FoxPlug from public releases; not affiliated with pnpm. An automatic summary of the public release, pull request and commit data of github.com/pnpm/pnpm. pnpm did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- pnpm can now prepare lockfile-less pnpm workspaces as git-hosted dependencies by detecting `pnpm-workspace.yaml`. Pull request #16301
- Fixed linking of `file:` dependencies that point to directories inside their own package. Pull request #16296
- Package publish now waits at least 5 minutes for the registry to accept uploads instead of timing out after 1 minute. Pull request #15863
- Fixed `--config` command-line tokens being silently ignored when they did not match a hand-written table of settings. Pull request #16280
- Filtered `pnpm run` and `pnpm exec` now install only the projects the filter selected instead of potentially running without their dependencies. Pull request #16211
- `pnpm install` in workspaces with `sharedWorkspaceLockfile: false` now runs projects concurrently instead of sequentially. Pull request #16263
- Workspace discovery no longer descends into hidden directories like `.cache` that the glob pattern excludes. Pull request #16252
- Windows pnpm binaries now statically link the C runtime so they run on clean Windows installs without the Visual C++ Redistributable. Pull request #15853
- Offline installs now resolve to store-held versions instead of failing when the newest cached version lacks a tarball. Pull request #15860
- `pnpm pack` and `pnpm publish` now ship files that the `files` field names even when it also excludes their parent directory. Pull request #16243
Why it matters
This week brings fixes for publish reliability, workspace handling, offline installs, and Windows compatibility. Several fixes address edge cases where pnpm would silently drop settings or dependencies, or fail entirely in valid scenarios. These improvements make pnpm more robust across different platforms and configurations.
Changelog entry
- fix(prepare-package): detect pnpm workspaces by pnpm-workspace.yaml when lockfile is missing Pull request #16301
- fix: link file: dependencies that point inside their package Pull request #16296
- fix(publish): wait at least 5 minutes for registry to accept uploads Pull request #15863
- fix(cli): apply all --config token overrides instead of silently dropping them Pull request #16280
- fix(exec): install only projects selected by filter instead of entire workspace Pull request #16211
- perf(install): run dedicated-lockfile projects concurrently Pull request #16263
- fix(workspace): skip hidden directories during workspace discovery Pull request #16252
- fix: statically link C runtime on Windows to remove Visual C++ Redistributable dependency Pull request #15853
- fix(resolver): resolve offline installs to store-held versions Pull request #15860
- fix(pack): include files named in files field despite directory exclusions Pull request #16243
- fix: preserve shared store ownership and group-write permissions Pull request #15882
- fix(config): reject invalid base64 _password values with error Pull request #16279
pnpm 12 and 11 updates: publish now waits 5 minutes for registries, filtered commands install only selected projects, workspaces run concurrently, Windows no longer needs Visual C++ Redistributable, and offline installs resolve correctly.
This week's pnpm releases fix critical issues across publishing, workspace management, and platform compatibility. Publish operations now wait 5 minutes for registry acceptance instead of timing out. Filtered pnpm run and exec commands install only required dependencies. Workspaces with independent lockfiles now install projects concurrently. Windows binaries now statically link the C runtime, removing the Visual C++ Redistributable requirement. Offline installs correctly resolve to cached versions, and workspace discovery no longer scans hidden directories.