AdmZip's Utils.writeFileTo opens each destination with fs.openSync(path,
"w"), which resolves symlinks, and Utils.sanitize only compares the entry
name as a string against the extraction root (GHSA-vwc7-r8mq-g2x9). A
symlink that already exists at a destination therefore redirects the write
anywhere the process can write. No patched adm-zip release exists.
extractZipToTarget extracted prefixed archives into path.dirname(targetDir),
which is the store's shared tmp directory, so every entry landed at the
fixed path <store>/tmp/<prefix>/... Node.js on Windows and Bun on every
platform set a prefix; Deno does not and already extracted into the random
directory from cafs.tempDir(). On a store shared by several users, another
user could pre-create a symlink at that fixed path and have pnpm overwrite
an arbitrary file. pnpm's own validatePathSecurity does not help: it checks
the entry string, which is exactly the check the advisory calls
insufficient.
Extract into a directory created with mkdtemp next to targetDir instead,
on the same filesystem so the rename stays cheap, and remove it afterwards.
That leaves no predictable destination to plant a link at, independent of
what adm-zip does.
The advisory is added to auditConfig.ignoreGhsas since no upgrade exists.
Reuse the existing URL-scoped registry credential lookup for every Node.js mirror request instead of introducing a separate authentication setting.
This covers release indexes, SHASUMS files and signatures, and runtime archives in both implementations while retaining longest-path-prefix scoping and cross-origin redirect protections. Authenticated checksum metadata bypasses the URL-keyed disk cache so it cannot cross credential contexts.
Closespnpm/pnpm#14334.
Remove the legacy repository changelog files now that release changelog storage defaults to the registry. The publish path composes and injects CHANGELOG.md into release tarballs, so keeping historical copies in source control duplicates generated release data.
Update adm-zip to the patched 0.6 release and override vulnerable transitive versions after the dependency audit began rejecting versions below 0.6.0.
The TypeScript pnpm CLI freezes at v11; pnpm 12 will be the Rust pacquet
port. To make that split legible, all TypeScript source, test, and build
directories move under a new top-level pnpm11/ directory. The name states
the version boundary rather than implying a behavioral fork, since the two
stacks are meant to behave identically.
Scope is source-only: the shared workspace root stays at the repo root.
pnpm-workspace.yaml, package.json, pnpm-lock.yaml, .pnpmfile.cjs,
.meta-updater, __patches__, .changeset, .husky, and the lint/spell configs
remain in place, so one pnpm workspace and one Cargo workspace still span
all three products. pnpr/client and pacquet/tasks/registry-mock stay as
cross-product workspace members.
Rewiring the move required:
- pnpm-workspace.yaml globs prefixed with pnpm11/
- root package.json script paths, eslint.config.mjs, tsconfig.lint.json,
.gitignore, and CODEOWNERS updated
- .meta-updater/src/index.ts literals repointed (pnpm11/pnpm/package.json,
pnpm11/__utils__, pnpm11/__typings__, and the main package directory)
- regenerated every moved package's repository/homepage URL via meta-updater
- pnpm11/pnpm/bundle-deps.ts and __utils__/scripts/src/typecheck-only.ts
climb one more level to reach the repo root
.meta-updater stays at the repo root because @pnpm/meta-updater resolves
its config at <cwd>/.meta-updater/main.mjs.
TS CI (.github/workflows/ci.yml) now only runs when pnpm11/-relevant paths
change, via a dorny/paths-filter changes job plus a TS CI / Success
aggregate gate; branch protection should require only that gate.