ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 40

  1. Blog

pnpm 12.9.1: Rust rewrite, @pnpm/wasm split, GitLab provenance (3 Oct 2026)

pnpm published v12.9.1 on 3 October 2026: WebContainer build moves to @pnpm/wasm, GitLab CI provenance publish fixed. npm latest=12.9.1 confirmed 5 Oct; ShopperCove upgrade checklist only; no affiliate.

Aditya Challa·5 October 2026·4 min read

Summary
On this page
  1. What lands in 12.9.1
  2. pnpm 12 baseline (why 12.x matters)
  3. Hands-on upgrade checklist
  4. Bottom line
  5. Sources
  6. Related

pnpm 12.9.1: Rust rewrite, @pnpm/wasm split, GitLab provenance (3 Oct 2026)

On 3 October 2026, pnpm published v12.9.1. ShopperCove did not migrate a production monorepo for this note and did not run install benchmarks. Package identity was confirmed on the npm registry on 5 October 2026 (pnpm@12.9.1, dist-tag latest and latest-12, npm time 2026-10-03T20:48:16.304Z). Primary sources: the GitHub release v12.9.1 (published 2026-10-03T20:48:42Z), the pnpm 12.9.1 blog, plus What's different in pnpm 12 and pnpm 12.0 for the Rust-rewrite baseline. This is a docs-based upgrade checklist—not performance advice and not a security advisory (no CVEs are claimed here).

There is no affiliate link in this article. This post has no affiliate links.

What lands in 12.9.1

From the 12.9.1 release notes:

AreaChange
WebContainer / sizeWebAssembly build for StackBlitz WebContainers ships as separate @pnpm/wasm; pnpm / @pnpm/exe unpack size back to about 4 MB (from ~55 MB)
Publish provenancepnpm publish with provenance from GitLab CI no longer rejected with npm 422; statement includes GitLab CI vars in invocation.parameters
Audit TLSpnpm audit signatures uses TLS settings of the redirect target when signing-keys requests redirect (e.g. to registry.npmjs.org)
Frozen lockfile--frozen-lockfile no longer rejects an up-to-date lockfile when an injected workspace package uses a catalog entry in peerDependencies
Filters / Git[] filter selector works again with Git 2.24–2.27; older Git fails with a clear version error; non-ASCII path change detection fixed
Homebrewpnpm self-update fails for Homebrew-installed pnpm and prints brew upgrade instead of installing a shadowed second copy
OtherSmaller pnpm executable (~10%); faster trust-downgrade checks; optimisticRepeatInstall: false still runs project lifecycle scripts when node_modules is up to date

WebContainer users: install @pnpm/wasm with npm inside the container to get the pnpm command after this split.

pnpm 12 baseline (why 12.x matters)

pnpm 12 is a Rust rewrite that stayed command/flag/lockfile compatible with 11 for most workflows. Official differences worth checking before you pin:

  1. Project-aware global bins — global node / deno / bun can defer to the version a project pins (devEngines.runtime / globalShims).
  2. Git dependency identity — GitHub/GitLab/Bitbucket specs resolve via HTTPS identity; lockfiles should not bake machine-specific SSH URLs for those hosts.
  3. Package-manager naming — pnpm add yarn / node / deno / bun means the tool, not the old npm wrapper package (use npm: aliases when you truly want the npm package).
  4. Cyclic graphs — peer/cycle cuts are deterministic; expect a one-time lockfile diff on first re-resolve.
  5. Linux packageImportMethod: auto — hardlink-first (clone second); macOS stays clone-first.
  6. engineStrict — incompatible engines fail even when the subtree sits under optionalDependencies if reached via regular dependencies.
  7. CLI removals — --resolution-only is gone (pnpm peers check instead); use --no-frozen-lockfile instead of --frozen-lockfile false.

Registry note: the August 2026 “What's different” post said npm latest still pointed at 11. As of sources read 5 Oct 2026, npm dist-tag latest is 12.9.1 (same as latest-12). Always verify with npm view pnpm version / npm view pnpm dist-tags before writing CI pins.

Hands-on upgrade checklist

  1. Inventory: pnpm -v (and whether install came from npm, corepack, Homebrew, or standalone).
  2. Confirm registry: npm view pnpm version → expect 12.9.1 as of 5 Oct 2026 sources.
  3. Staging bump: install / self-update to 12.9.1 on a branch; prefer an explicit pin in packageManager / CI image.
  4. Re-resolve once: if you still carry pnpm 11 cyclic lockfile peer variants, expect a one-time lockfile rewrite when resolution runs—review the diff before --frozen-lockfile CI.
  5. GitLab provenance publishers: re-test pnpm publish with provenance after 12.9.1 if you hit 422s.
  6. WebContainer / size-sensitive installs: if you relied on the in-package WASM build, add @pnpm/wasm where needed.
  7. Homebrew users: use brew upgrade pnpm (or the formula pin pnpm prints)—do not fight self-update.
  8. Do not invent security urgency: this note is features + bugfixes from official blogs; ShopperCove is not attaching CVE IDs.

ShopperCove did not change production pnpm versions for this article. Prefer pnpm.io release blogs and the GitHub release over third-party roundups.

Bottom line

pnpm v12.9.1 (3 Oct 2026) splits WebContainer WASM into @pnpm/wasm, shrinks the main package again, and fixes GitLab CI provenance publishing—on top of the pnpm 12 Rust-rewrite line. Pin pnpm@12.9.1 when ready. No affiliate.

Sources

  • https://pnpm.io/blog/releases/12.9.1
  • https://github.com/pnpm/pnpm/releases/tag/v12.9.1
  • https://pnpm.io/blog/whats-different-in-pnpm-12
  • https://pnpm.io/blog/releases/12.0
  • https://registry.npmjs.org/pnpm/12.9.1
  • https://pnpm.io/

Related

  • https://www.shoppercove.com/blog/vite-plus-1-0-unified-toolchain-october-2026
  • https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
  • https://www.shoppercove.com/blog/eslint-10-12-release-october-2026
  • https://www.shoppercove.com/blog/oxlint-1-87-react-suggestions-a11y-fixes-october-2026
  • https://www.shoppercove.com/blog/typescript-eslint-8-71-no-unsafe-enum-assignment-october-2026
  • https://www.shoppercove.com/blog/webpack-5-111-esm-output-stable-september-2026
  • https://www.shoppercove.com/blog/playwright-1-63-test-locks-october-2026
  • https://www.shoppercove.com/blog/astro-starlight-0-42-popover-js-dist-october-2026
pnpmrustwasmgitlabpackage managerwebcontainerprovenance

Lab evidence

What I found running this

Sources read 5 Oct 2026 (Asia/Calcutta): npm registry dist-tags latest=12.9.1 and latest-12=12.9.1 (time 2026-10-03T20:48:16.304Z); GitHub release v12.9.1 published 2026-10-03T20:48:42Z; pnpm blog 12.9.1 (WebContainer build → @pnpm/wasm; pnpm unpack ~4 MB; GitLab CI provenance publish fix; audit signatures TLS on redirect; frozen-lockfile+injected catalog peers; [] filter Git 2.24–2.27; self-update Homebrew refuse); What's different in pnpm 12 (2026-08-10) + 12.0 stable (2026-08-26) Rust rewrite notes — project-aware global bins, git HTTPS identity, package-manager naming, cyclic lockfile determinism, Linux hardlink-first auto, engineStrict through optional subtrees, --resolution-only removed, --no-frozen-lockfile. Note: Aug blog said npm latest still 11; as of 5 Oct 2026 registry latest is 12.9.1. Checklist only; no ShopperCove monorepo migrated; no affiliate.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Introducing CUDA Rust: Two Tracks for Writing GPU Kernels

    NVIDIA now lets you write CUDA kernels natively in Rust, compiled to PTX, through two separate projects: cuda-oxide for SIMT and cutile-rs for the tile model.

    10 Sept 2026

  • Plate 33

    vue-tsc 3.3.12 TS2300 Duplicate $style: Should You Upgrade?

    vue-tsc / Vue Language Tools 3.3.12 (2 Oct 2026): ShopperCove reproduced TS2300 "Duplicate identifier $style" on a two-<style module> fixture—absent on 3.3.11. Also: defineModel default-factory typing, untrusted SFC hardening, template .value call fix. Upgrade decision for Vue teams. No affiliate.

    5 Oct 2026

  • Plate 05

    oxfmt 0.72: native Markdown formatter, Prettier 3.9.9 parity test, sorted imports in code fences (5 Oct 2026)

    oxfmt 0.72.0 (5 Oct 2026) swaps its Prettier-backed Markdown path for the native oxc_formatter_markdown (breaking). ShopperCove formatted 221 Markdown drafts with oxfmt 0.71.0, 0.72.0 and Prettier 3.9.9: byte-identical output, ~2 s vs ~16 ms. Plus opt-in import sorting inside code fences, the documented divergences, ignore-file and LSP fixes. No affiliate links.

    5 Oct 2026

On this page

  1. What lands in 12.9.1
  2. pnpm 12 baseline (why 12.x matters)
  3. Hands-on upgrade checklist
  4. Bottom line
  5. Sources
  6. Related
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove