Plate 40
pnpm 12.9.1: Rust rewrite, @pnpm/wasm split, GitLab provenance (3 Oct 2026)
pnpm published v12.9.1 on 3 October 2026: WebContainer build moves to @pnpm/wasm, GitLab CI provenance publish fixed. npm latest=12.9.1 confirmed 5 Oct; ShopperCove upgrade checklist only; no affiliate.
Aditya Challa4 min read
pnpm 12.9.1: Rust rewrite, @pnpm/wasm split, GitLab provenance (3 Oct 2026)
On 3 October 2026, pnpm published v12.9.1. ShopperCove did not migrate a production monorepo for this note and did not run install benchmarks. Package identity was confirmed on the npm registry on 5 October 2026 (pnpm@12.9.1, dist-tag latest and latest-12, npm time 2026-10-03T20:48:16.304Z). Primary sources: the GitHub release v12.9.1 (published 2026-10-03T20:48:42Z), the pnpm 12.9.1 blog, plus What's different in pnpm 12 and pnpm 12.0 for the Rust-rewrite baseline. This is a docs-based upgrade checklist—not performance advice and not a security advisory (no CVEs are claimed here).
There is no affiliate link in this article. This post has no affiliate links.
What lands in 12.9.1
From the 12.9.1 release notes:
| Area | Change |
|---|---|
| WebContainer / size | WebAssembly build for StackBlitz WebContainers ships as separate @pnpm/wasm; pnpm / @pnpm/exe unpack size back to about 4 MB (from ~55 MB) |
| Publish provenance | pnpm publish with provenance from GitLab CI no longer rejected with npm 422; statement includes GitLab CI vars in invocation.parameters |
| Audit TLS | pnpm audit signatures uses TLS settings of the redirect target when signing-keys requests redirect (e.g. to registry.npmjs.org) |
| Frozen lockfile | --frozen-lockfile no longer rejects an up-to-date lockfile when an injected workspace package uses a catalog entry in peerDependencies |
| Filters / Git | [] filter selector works again with Git 2.24–2.27; older Git fails with a clear version error; non-ASCII path change detection fixed |
| Homebrew | pnpm self-update fails for Homebrew-installed pnpm and prints brew upgrade instead of installing a shadowed second copy |
| Other | Smaller pnpm executable (~10%); faster trust-downgrade checks; optimisticRepeatInstall: false still runs project lifecycle scripts when node_modules is up to date |
WebContainer users: install @pnpm/wasm with npm inside the container to get the pnpm command after this split.
pnpm 12 baseline (why 12.x matters)
pnpm 12 is a Rust rewrite that stayed command/flag/lockfile compatible with 11 for most workflows. Official differences worth checking before you pin:
- Project-aware global bins — global
node/deno/buncan defer to the version a project pins (devEngines.runtime/globalShims). - Git dependency identity — GitHub/GitLab/Bitbucket specs resolve via HTTPS identity; lockfiles should not bake machine-specific SSH URLs for those hosts.
- Package-manager naming —
pnpm add yarn/node/deno/bunmeans the tool, not the old npm wrapper package (usenpm:aliases when you truly want the npm package). - Cyclic graphs — peer/cycle cuts are deterministic; expect a one-time lockfile diff on first re-resolve.
- Linux
packageImportMethod: auto— hardlink-first (clone second); macOS stays clone-first. engineStrict— incompatible engines fail even when the subtree sits underoptionalDependenciesif reached via regulardependencies.- CLI removals —
--resolution-onlyis gone (pnpm peers checkinstead); use--no-frozen-lockfileinstead of--frozen-lockfile false.
Registry note: the August 2026 “What's different” post said npm latest still pointed at 11. As of sources read 5 Oct 2026, npm dist-tag latest is 12.9.1 (same as latest-12). Always verify with npm view pnpm version / npm view pnpm dist-tags before writing CI pins.
Hands-on upgrade checklist
- Inventory:
pnpm -v(and whether install came from npm, corepack, Homebrew, or standalone). - Confirm registry:
npm view pnpm version→ expect 12.9.1 as of 5 Oct 2026 sources. - Staging bump: install / self-update to 12.9.1 on a branch; prefer an explicit pin in
packageManager/ CI image. - Re-resolve once: if you still carry pnpm 11 cyclic lockfile peer variants, expect a one-time lockfile rewrite when resolution runs—review the diff before
--frozen-lockfileCI. - GitLab provenance publishers: re-test
pnpm publishwith provenance after 12.9.1 if you hit 422s. - WebContainer / size-sensitive installs: if you relied on the in-package WASM build, add
@pnpm/wasmwhere needed. - Homebrew users: use
brew upgrade pnpm(or the formula pin pnpm prints)—do not fightself-update. - Do not invent security urgency: this note is features + bugfixes from official blogs; ShopperCove is not attaching CVE IDs.
ShopperCove did not change production pnpm versions for this article. Prefer pnpm.io release blogs and the GitHub release over third-party roundups.
Bottom line
pnpm v12.9.1 (3 Oct 2026) splits WebContainer WASM into @pnpm/wasm, shrinks the main package again, and fixes GitLab CI provenance publishing—on top of the pnpm 12 Rust-rewrite line. Pin pnpm@12.9.1 when ready. No affiliate.
Sources
- https://pnpm.io/blog/releases/12.9.1
- https://github.com/pnpm/pnpm/releases/tag/v12.9.1
- https://pnpm.io/blog/whats-different-in-pnpm-12
- https://pnpm.io/blog/releases/12.0
- https://registry.npmjs.org/pnpm/12.9.1
- https://pnpm.io/
Related
- https://www.shoppercove.com/blog/vite-plus-1-0-unified-toolchain-october-2026
- https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
- https://www.shoppercove.com/blog/eslint-10-12-release-october-2026
- https://www.shoppercove.com/blog/oxlint-1-87-react-suggestions-a11y-fixes-october-2026
- https://www.shoppercove.com/blog/typescript-eslint-8-71-no-unsafe-enum-assignment-october-2026
- https://www.shoppercove.com/blog/webpack-5-111-esm-output-stable-september-2026
- https://www.shoppercove.com/blog/playwright-1-63-test-locks-october-2026
- https://www.shoppercove.com/blog/astro-starlight-0-42-popover-js-dist-october-2026
Lab evidence
What I found running this
Sources read 5 Oct 2026 (Asia/Calcutta): npm registry dist-tags latest=12.9.1 and latest-12=12.9.1 (time 2026-10-03T20:48:16.304Z); GitHub release v12.9.1 published 2026-10-03T20:48:42Z; pnpm blog 12.9.1 (WebContainer build → @pnpm/wasm; pnpm unpack ~4 MB; GitLab CI provenance publish fix; audit signatures TLS on redirect; frozen-lockfile+injected catalog peers; [] filter Git 2.24–2.27; self-update Homebrew refuse); What's different in pnpm 12 (2026-08-10) + 12.0 stable (2026-08-26) Rust rewrite notes — project-aware global bins, git HTTPS identity, package-manager naming, cyclic lockfile determinism, Linux hardlink-first auto, engineStrict through optional subtrees, --resolution-only removed, --no-frozen-lockfile. Note: Aug blog said npm latest still 11; as of 5 Oct 2026 registry latest is 12.9.1. Checklist only; no ShopperCove monorepo migrated; no affiliate.
Related links
Introducing CUDA Rust: Two Tracks for Writing GPU Kernels
NVIDIA now lets you write CUDA kernels natively in Rust, compiled to PTX, through two separate projects: cuda-oxide for SIMT and cutile-rs for the tile model.
10 Sept 2026
Plate 33
vue-tsc 3.3.12 TS2300 Duplicate $style: Should You Upgrade?
vue-tsc / Vue Language Tools 3.3.12 (2 Oct 2026): ShopperCove reproduced TS2300 "Duplicate identifier $style" on a two-<style module> fixture—absent on 3.3.11. Also: defineModel default-factory typing, untrusted SFC hardening, template .value call fix. Upgrade decision for Vue teams. No affiliate.
5 Oct 2026
Plate 05
oxfmt 0.72: native Markdown formatter, Prettier 3.9.9 parity test, sorted imports in code fences (5 Oct 2026)
oxfmt 0.72.0 (5 Oct 2026) swaps its Prettier-backed Markdown path for the native oxc_formatter_markdown (breaking). ShopperCove formatted 221 Markdown drafts with oxfmt 0.71.0, 0.72.0 and Prettier 3.9.9: byte-identical output, ~2 s vs ~16 ms. Plus opt-in import sorting inside code fences, the documented divergences, ignore-file and LSP fixes. No affiliate links.
5 Oct 2026