pnpm 10: dependency lifecycle scripts blocked by default
pnpm 10: dependency lifecycle scripts blocked by default
pnpm 10 (Jan 2025) stops executing lifecycle scripts of dependencies during install unless explicitly allowlisted via onlyBuiltDependencies — a supply-chain hardening that breaks naive esbuild/sharp installs.
pnpm 10
As of: 2025-01, verified 2026-09
The headline change
Dependency lifecycle scripts (postinstall etc.) no longer run during install by default. Packages needing native builds (esbuild, sharp, @swc/core, husky-like tools installed as deps) silently stop working until allowlisted:
{ "pnpm": { "onlyBuiltDependencies": ["esbuild", "sharp"] } }
pnpm prints which packages were skipped — read install output, don't ignore it.
Why it matters
Post-install scripts are the #1 npm supply-chain exfiltration vector (see the npm supply chain 2026 entry). pnpm 10 turns the ecosystem's worst default into an allowlist. Combined with pnpm's strict node_modules layout and lockfile discipline, it's the hardest package-manager default in 2026.
Also in 10.x
- Root-level
pnpm.overridesbehavior changes forpnpm link. - Config in
pnpm-workspace.yamlconsolidates workspace settings. - Faster resolution cache; audit fixes (
pnpm audit --fix).