diff --git a/doc/languages-frameworks/javascript.section.md b/doc/languages-frameworks/javascript.section.md index 24061021d125..48f6bfdab47a 100644 --- a/doc/languages-frameworks/javascript.section.md +++ b/doc/languages-frameworks/javascript.section.md @@ -306,6 +306,7 @@ This package puts the corepack wrappers for pnpm and yarn in your PATH, and they ### pnpm {#javascript-pnpm} pnpm is available as the top-level package `pnpm`. Additionally, there are variants pinned to certain major versions, like `pnpm_8`, `pnpm_9`, `pnpm_10`, `pnpm_10_29_2` and `pnpm_11`, which support different sets of lock file versions. +`pnpm_10_latest` tracks the latest pnpm 10 release, while `pnpm_10` remains fixed for compatibility. When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` will prepare the build environment to install the pre-fetched dependencies store. Here is an example for a package that contains `package.json` and a `pnpm-lock.yaml` files using the fetcher and setup hook above: diff --git a/pkgs/development/tools/pnpm/default.nix b/pkgs/development/tools/pnpm/default.nix index cbb8f1826e8c..6c3f27c7294c 100644 --- a/pkgs/development/tools/pnpm/default.nix +++ b/pkgs/development/tools/pnpm/default.nix @@ -17,6 +17,11 @@ let "CVE-2026-50017" "CVE-2026-50573" "CVE-2026-55699" + "CVE-2026-59194" + "CVE-2026-59195" + "CVE-2026-59196" + "CVE-2026-82392" + "CVE-2026-82393" ]; }; "9" = { @@ -30,6 +35,11 @@ let "CVE-2026-50017" "CVE-2026-50573" "CVE-2026-55699" + "CVE-2026-59194" + "CVE-2026-59195" + "CVE-2026-59196" + "CVE-2026-82392" + "CVE-2026-82393" ]; }; # 10.29.3 made a breaking change: https://github.com/pnpm/pnpm/issues/10601. @@ -38,6 +48,7 @@ let "10_29_2" = { version = "10.29.2"; hash = "sha256-hAL2daH0zJ1PJ7v6s1wtSi4dfrATHfA9rQlhnoZnTQw="; + enableUpdateScript = false; knownVulnerabilities = [ "CVE-2026-48995" "CVE-2026-50014" @@ -46,11 +57,34 @@ let "CVE-2026-50017" "CVE-2026-50573" "CVE-2026-55699" + "CVE-2026-59194" + "CVE-2026-59195" + "CVE-2026-59196" + "CVE-2026-82392" + "CVE-2026-82393" ]; }; + # 10.34.1 tightened remote tarball integrity checks, which can break existing lockfiles. + # Keep the compatibility variant at 10.34.0 for out-of-tree consumers. "10" = { version = "10.34.0"; hash = "sha256-WOFDJYhx31FYm2UcBiBdq+xIdmpdu6PCWZm2m1C+WY4="; + enableUpdateScript = false; + knownVulnerabilities = [ + "CVE-2026-55487" + "CVE-2026-55698" + "CVE-2026-55180" + "CVE-2026-55697" + "CVE-2026-59194" + "CVE-2026-59195" + "CVE-2026-59196" + "CVE-2026-82392" + "CVE-2026-82393" + ]; + }; + "10_latest" = { + version = "10.34.5"; + hash = "sha256-zLXEecqxsAYhMlv+fUyaioAx56Ul1ySeJ17L7IGwjbI="; }; "11" = { version = "11.27.0"; @@ -64,10 +98,11 @@ let }; callPnpmNode = - variant: + packageAttrName: variant: callPackage ./generic.nix ( variant // { + inherit packageAttrName; #FIXME: remove this hack in a future version. nodejs = null; # Passing null to detect out-of-tree overrides } @@ -75,8 +110,15 @@ let callPnpmRust = callPackage ./generic-rust.nix; - callPnpm = variant: if variant ? cargoHash then callPnpmRust variant else callPnpmNode variant; + callPnpm = + packageAttrName: variant: + if variant ? cargoHash then callPnpmRust variant else callPnpmNode packageAttrName variant; - mkPnpm = versionSuffix: variant: nameValuePair "pnpm_${versionSuffix}" (callPnpm variant); + mkPnpm = + versionSuffix: variant: + let + packageAttrName = "pnpm_${versionSuffix}"; + in + nameValuePair packageAttrName (callPnpm packageAttrName variant); in mapAttrs' mkPnpm variants diff --git a/pkgs/development/tools/pnpm/generic.nix b/pkgs/development/tools/pnpm/generic.nix index 0f6e5fe36d3a..3cb6508da520 100644 --- a/pkgs/development/tools/pnpm/generic.nix +++ b/pkgs/development/tools/pnpm/generic.nix @@ -15,6 +15,8 @@ tests, withNode ? true, + enableUpdateScript ? true, + packageAttrName ? "pnpm_${lib.versions.major version}", version, hash, knownVulnerabilities ? [ ], @@ -95,7 +97,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { passthru = let - pnpm' = buildPackages."pnpm_${lib.versions.major version}"; + pnpm' = buildPackages.${packageAttrName}; in { fetchDeps = @@ -129,6 +131,8 @@ stdenvNoCC.mkDerivation (finalAttrs: { inherit (tests) pnpm; version = lib.optionalAttrs withNode (testers.testVersion { package = finalAttrs.finalPackage; }); }; + } + // lib.optionalAttrs enableUpdateScript { updateScript = writeScript "pnpm-update-script" '' #!/usr/bin/env nix-shell #!nix-shell -i bash -p curl jq common-updater-scripts @@ -152,7 +156,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { latestVersion="''${latestTag#v}" - update-source-version pnpm_${majorVersion} "$latestVersion" --file=./pkgs/development/tools/pnpm/default.nix + update-source-version ${packageAttrName} "$latestVersion" --file=./pkgs/development/tools/pnpm/default.nix ''; }; diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index b322bf029b99..0ee337364fc5 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -2960,6 +2960,7 @@ with pkgs; pnpm_9 pnpm_10_29_2 pnpm_10 + pnpm_10_latest pnpm_11 pnpm_12 ;