ended5월 13일· 1 sources
pnpm 11 Hardens npm Against Supply Chain Attacks
TanStack 공격이 촉발한 npm 보안 혁신, pnpm 11의 새로운 기본값
Why it matters
The TanStack npm attack demonstrated how vulnerable package managers remain to malicious actors exploiting CI/CD weaknesses and cache poisoning techniques. pnpm 11 responds with new security defaults—including a 24-hour delay on new package installations and stricter dependency verification—representing an industry shift from convenience-first to secure-by-default package management. For developers, this means significantly reduced transitive dependency attack risks without requiring manual security configuration.
1
Sources
+0
24h
—
Growth
130d
Active
npm supply chainpnpm 11GitHub Actionscache poisoningdependency verification