pnpm_10_latest: init at 10.34.5

Keep pnpm_10 at 10.34.0 for out-of-tree compatibility and mark it
insecure. Add pnpm_10_latest at 10.34.5 and make variant generation
and updater targets attribute-specific.

Not-cherry-picked-because: release-26.05 has different pnpm variants and lockfiles
Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)
This commit is contained in:
Gerhard Schwanzer
2026-09-11 20:12:17 +02:00
parent 265f53ffc8
commit 89a606c108
4 changed files with 53 additions and 5 deletions

View File

@@ -306,6 +306,7 @@ This package puts the corepack wrappers for pnpm and yarn in your PATH, and they
### pnpm {#javascript-pnpm}
pnpm is available as the top-level package `pnpm`. Additionally, there are variants pinned to certain major versions, like `pnpm_8`, `pnpm_9`, `pnpm_10`, `pnpm_10_29_2` and `pnpm_11`, which support different sets of lock file versions.
`pnpm_10_latest` tracks the latest pnpm 10 release, while `pnpm_10` remains fixed for compatibility.
When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` will prepare the build environment to install the pre-fetched dependencies store. Here is an example for a package that contains `package.json` and a `pnpm-lock.yaml` files using the fetcher and setup hook above:

View File

@@ -17,6 +17,11 @@ let
"CVE-2026-50017"
"CVE-2026-50573"
"CVE-2026-55699"
"CVE-2026-59194"
"CVE-2026-59195"
"CVE-2026-59196"
"CVE-2026-82392"
"CVE-2026-82393"
];
};
"9" = {
@@ -30,6 +35,11 @@ let
"CVE-2026-50017"
"CVE-2026-50573"
"CVE-2026-55699"
"CVE-2026-59194"
"CVE-2026-59195"
"CVE-2026-59196"
"CVE-2026-82392"
"CVE-2026-82393"
];
};
# 10.29.3 made a breaking change: https://github.com/pnpm/pnpm/issues/10601.
@@ -38,6 +48,7 @@ let
"10_29_2" = {
version = "10.29.2";
hash = "sha256-hAL2daH0zJ1PJ7v6s1wtSi4dfrATHfA9rQlhnoZnTQw=";
enableUpdateScript = false;
knownVulnerabilities = [
"CVE-2026-48995"
"CVE-2026-50014"
@@ -46,11 +57,34 @@ let
"CVE-2026-50017"
"CVE-2026-50573"
"CVE-2026-55699"
"CVE-2026-59194"
"CVE-2026-59195"
"CVE-2026-59196"
"CVE-2026-82392"
"CVE-2026-82393"
];
};
# 10.34.1 tightened remote tarball integrity checks, which can break existing lockfiles.
# Keep the compatibility variant at 10.34.0 for out-of-tree consumers.
"10" = {
version = "10.34.0";
hash = "sha256-WOFDJYhx31FYm2UcBiBdq+xIdmpdu6PCWZm2m1C+WY4=";
enableUpdateScript = false;
knownVulnerabilities = [
"CVE-2026-55487"
"CVE-2026-55698"
"CVE-2026-55180"
"CVE-2026-55697"
"CVE-2026-59194"
"CVE-2026-59195"
"CVE-2026-59196"
"CVE-2026-82392"
"CVE-2026-82393"
];
};
"10_latest" = {
version = "10.34.5";
hash = "sha256-zLXEecqxsAYhMlv+fUyaioAx56Ul1ySeJ17L7IGwjbI=";
};
"11" = {
version = "11.27.0";
@@ -64,10 +98,11 @@ let
};
callPnpmNode =
variant:
packageAttrName: variant:
callPackage ./generic.nix (
variant
// {
inherit packageAttrName;
#FIXME: remove this hack in a future version.
nodejs = null; # Passing null to detect out-of-tree overrides
}
@@ -75,8 +110,15 @@ let
callPnpmRust = callPackage ./generic-rust.nix;
callPnpm = variant: if variant ? cargoHash then callPnpmRust variant else callPnpmNode variant;
callPnpm =
packageAttrName: variant:
if variant ? cargoHash then callPnpmRust variant else callPnpmNode packageAttrName variant;
mkPnpm = versionSuffix: variant: nameValuePair "pnpm_${versionSuffix}" (callPnpm variant);
mkPnpm =
versionSuffix: variant:
let
packageAttrName = "pnpm_${versionSuffix}";
in
nameValuePair packageAttrName (callPnpm packageAttrName variant);
in
mapAttrs' mkPnpm variants

View File

@@ -15,6 +15,8 @@
tests,
withNode ? true,
enableUpdateScript ? true,
packageAttrName ? "pnpm_${lib.versions.major version}",
version,
hash,
knownVulnerabilities ? [ ],
@@ -95,7 +97,7 @@ stdenvNoCC.mkDerivation (finalAttrs: {
passthru =
let
pnpm' = buildPackages."pnpm_${lib.versions.major version}";
pnpm' = buildPackages.${packageAttrName};
in
{
fetchDeps =
@@ -129,6 +131,8 @@ stdenvNoCC.mkDerivation (finalAttrs: {
inherit (tests) pnpm;
version = lib.optionalAttrs withNode (testers.testVersion { package = finalAttrs.finalPackage; });
};
}
// lib.optionalAttrs enableUpdateScript {
updateScript = writeScript "pnpm-update-script" ''
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p curl jq common-updater-scripts
@@ -152,7 +156,7 @@ stdenvNoCC.mkDerivation (finalAttrs: {
latestVersion="''${latestTag#v}"
update-source-version pnpm_${majorVersion} "$latestVersion" --file=./pkgs/development/tools/pnpm/default.nix
update-source-version ${packageAttrName} "$latestVersion" --file=./pkgs/development/tools/pnpm/default.nix
'';
};

View File

@@ -2960,6 +2960,7 @@ with pkgs;
pnpm_9
pnpm_10_29_2
pnpm_10
pnpm_10_latest
pnpm_11
pnpm_12
;