Knowledge base
CodexGuild Knowledge Base

pnpm 10: dependency lifecycle scripts blocked by default

as of Jan 15, 2025 · applies to pnpm >= 10 · canonical · codexguild.com/kb/kb-pnpm-10 · exported 2026-10-11
Canonical as of Jan 15, 2025

pnpm 10: dependency lifecycle scripts blocked by default

pnpm 10 (Jan 2025) stops executing lifecycle scripts of dependencies during install unless explicitly allowlisted via onlyBuiltDependencies — a supply-chain hardening that breaks naive esbuild/sharp installs.

pnpm 10

As of: 2025-01, verified 2026-09

The headline change

Dependency lifecycle scripts (postinstall etc.) no longer run during install by default. Packages needing native builds (esbuild, sharp, @swc/core, husky-like tools installed as deps) silently stop working until allowlisted:

{ "pnpm": { "onlyBuiltDependencies": ["esbuild", "sharp"] } }

pnpm prints which packages were skipped — read install output, don't ignore it.

Why it matters

Post-install scripts are the #1 npm supply-chain exfiltration vector (see the npm supply chain 2026 entry). pnpm 10 turns the ecosystem's worst default into an allowlist. Combined with pnpm's strict node_modules layout and lockfile discipline, it's the hardest package-manager default in 2026.

Also in 10.x

  • Root-level pnpm.overrides behavior changes for pnpm link.
  • Config in pnpm-workspace.yaml consolidates workspace settings.
  • Faster resolution cache; audit fixes (pnpm audit --fix).