{"name":"pnpm@9","full_name":"pnpm@9","tap":"homebrew/core","oldnames":[],"aliases":[],"versioned_formulae":["pnpm@11","pnpm@10"],"desc":"Fast, disk space efficient package manager","license":"MIT","homepage":"https://pnpm.io/","versions":{"stable":"9.15.9","head":null,"bottle":true},"urls":{"stable":{"url":"https://registry.npmjs.org/pnpm/-/pnpm-9.15.9.tgz","tag":null,"revision":null,"using":null,"checksum":"cf86a7ad764406395d4286a6d09d730711720acc6d93e9dce9ac7ac4dc4a28a7"}},"patches":[],"revision":0,"version_scheme":0,"compatibility_version":null,"autobump":true,"no_autobump_message":null,"skip_livecheck":false,"bottle":{"stable":{"rebuild":0,"root_url":"https://ghcr.io/v2/homebrew/core","files":{"arm64_golden_gate":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:1cd0a0d0c4538c8c6e0a4f9bac096310168e0418922df6697360d377f0221dac","sha256":"1cd0a0d0c4538c8c6e0a4f9bac096310168e0418922df6697360d377f0221dac"},"arm64_tahoe":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:065dfbb68112b1fa1f55b86a0e575944b20811fe2e50a9dc87761c88067d232d","sha256":"065dfbb68112b1fa1f55b86a0e575944b20811fe2e50a9dc87761c88067d232d"},"arm64_sequoia":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:ae74b37d814b99dd613cb07f94b593dab2bb1dca09ff9ade108ff180aba53db5","sha256":"ae74b37d814b99dd613cb07f94b593dab2bb1dca09ff9ade108ff180aba53db5"},"arm64_sonoma":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:ae74b37d814b99dd613cb07f94b593dab2bb1dca09ff9ade108ff180aba53db5","sha256":"ae74b37d814b99dd613cb07f94b593dab2bb1dca09ff9ade108ff180aba53db5"},"arm64_ventura":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:ae74b37d814b99dd613cb07f94b593dab2bb1dca09ff9ade108ff180aba53db5","sha256":"ae74b37d814b99dd613cb07f94b593dab2bb1dca09ff9ade108ff180aba53db5"},"sonoma":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:4ecc62fb50f7704d9afa60dc3e161ec772c59f85d0df91808813f26bd7fe3ace","sha256":"4ecc62fb50f7704d9afa60dc3e161ec772c59f85d0df91808813f26bd7fe3ace"},"ventura":{"cellar":":any","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:4ecc62fb50f7704d9afa60dc3e161ec772c59f85d0df91808813f26bd7fe3ace","sha256":"4ecc62fb50f7704d9afa60dc3e161ec772c59f85d0df91808813f26bd7fe3ace"},"arm64_linux":{"cellar":":any_skip_relocation","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:b604d8e5694ed2c72031680e1ad2a3b56a88dc9a808c6714f47969ecd7ccd02d","sha256":"b604d8e5694ed2c72031680e1ad2a3b56a88dc9a808c6714f47969ecd7ccd02d"},"x86_64_linux":{"cellar":":any_skip_relocation","url":"https://ghcr.io/v2/homebrew/core/pnpm/9/blobs/sha256:b604d8e5694ed2c72031680e1ad2a3b56a88dc9a808c6714f47969ecd7ccd02d","sha256":"b604d8e5694ed2c72031680e1ad2a3b56a88dc9a808c6714f47969ecd7ccd02d"}}}},"pour_bottle_only_if":null,"keg_only":true,"keg_only_reason":{"reason":":versioned_formula","explanation":""},"options":[],"build_dependencies":["node"],"dependencies":[],"test_dependencies":["node"],"recommended_dependencies":[],"optional_dependencies":[],"uses_from_macos":[],"uses_from_macos_bounds":[],"requirements":[],"conflicts_with":[],"conflicts_with_reasons":[],"link_overwrite":[],"caveats":"pnpm requires a Node installation to function. You can install one with:\n  brew install node\n","installed":[],"linked_keg":null,"pinned":false,"outdated":false,"deprecated":true,"deprecation_date":"2026-08-06","deprecation_reason":"unsupported","deprecation_replacement_formula":null,"deprecation_replacement_cask":null,"deprecate_args":{"date":"2026-08-06","because":"unsupported","replacement_formula":null,"replacement_cask":null},"disabled":false,"disable_date":"2027-02-06","disable_reason":null,"disable_replacement_formula":null,"disable_replacement_cask":null,"disable_args":{"date":"2027-02-06","because":"unsupported","replacement_formula":null,"replacement_cask":null},"post_install_steps":[],"post_install_defined":false,"service":null,"tap_git_head":"155d9a473d8cfee0215a5670557917cf7de76254","ruby_source_path":"Formula/p/pnpm@9.rb","ruby_source_checksum":{"sha256":"88ee140a3a6e065dc5903fb79a8ab407c17683c9e2e50938a283c86cf1935654"},"variations":{},"executables":["pnpm","pnpm@9","pnpx","pnpx@9"],"vulnerabilities":{"open":[{"id":"BREW-pnpm@9-CVE-2024-47829","upstream":["GHSA-8cc4-rfj6-fhg4","CVE-2024-47829"],"summary":"pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2025-69262","upstream":["GHSA-2phv-j68v-wwqx","CVE-2025-69262"],"summary":"pnpm vulnerable to Command Injection via environment variable substitution","severity":"high"},{"id":"BREW-pnpm@9-CVE-2025-69263","upstream":["GHSA-7vhp-vf5g-r2fw","CVE-2025-69263"],"summary":"pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-23888","upstream":["GHSA-6pfh-p556-v868","CVE-2026-23888"],"summary":"pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-23889","upstream":["GHSA-6x96-7vc8-cm3p","CVE-2026-23889"],"summary":"pnpm has Windows-specific tarball Path Traversal","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-23890","upstream":["GHSA-xpqm-wm3m-f34h","CVE-2026-23890"],"summary":"pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-24056","upstream":["GHSA-m733-5w8f-5ggw","CVE-2026-24056"],"summary":"pnpm has symlink traversal in file:/git dependencies","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-24131","upstream":["GHSA-v253-rj99-jwpq","CVE-2026-24131"],"summary":"pnpm has Path Traversal via arbitrary file permission modification "},{"id":"BREW-pnpm@9-CVE-2026-48995","upstream":["GHSA-hg3w-7f8c-63hp","CVE-2026-48995"],"summary":"pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile"},{"id":"BREW-pnpm@9-CVE-2026-50014","upstream":["GHSA-p4xf-rf54-rj3x","CVE-2026-50014"],"summary":"pnpm: Git Fetch Argument Injection via Lockfile resolution.commit","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-50015","upstream":["GHSA-rxhj-4m44-96r4","CVE-2026-50015"],"summary":"pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-50016","upstream":["GHSA-hwx4-2j3j-g496","CVE-2026-50016"],"summary":"pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-50017","upstream":["GHSA-cjhr-43r9-cfmw","CVE-2026-50017"],"summary":"pnpm binds unscoped user-level npm auth credentials to a repository-selected registry"},{"id":"BREW-pnpm@9-CVE-2026-50021","upstream":["GHSA-q6j5-fjx5-2mc3","CVE-2026-50021"],"summary":"pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-50573","upstream":["GHSA-54hh-g5mx-jqcp","CVE-2026-50573"],"summary":"pnpm: Unsafe default behavior breaks integrity check","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-55180","upstream":["GHSA-3qhv-2rgh-x77r","CVE-2026-55180"],"summary":"pnpm: Repository config can expand victim environment secrets into registry requests before scripts run","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-55487","upstream":["GHSA-5wx6-mg75-v57r","CVE-2026-55487"],"summary":"pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-55697","upstream":["GHSA-gj8w-mvpf-x27x","CVE-2026-55697"],"summary":"pnpm: Repository-controlled configDependencies can select a pacquet native install engine","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-55698","upstream":["GHSA-w466-c33r-3gjp","CVE-2026-55698"],"summary":"pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-55699","upstream":["GHSA-4gxm-v5v7-fqc4","CVE-2026-55699"],"summary":"pnpm: Reserved bin name deletes PNPM_HOME during global remove","severity":"medium"},{"id":"BREW-pnpm@9-CVE-2026-59194","upstream":["GHSA-72r4-9c5j-mj57","CVE-2026-59194"],"summary":"pnpm: `patch-remove` could delete project-selected files outside the patches directory","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-59195","upstream":["GHSA-qrv3-253h-g69c","CVE-2026-59195"],"summary":"pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-59196","upstream":["GHSA-fr4h-3cph-29xv","CVE-2026-59196"],"summary":"pnpm: Hoisted install imports lockfile alias outside node_modules","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-82392","upstream":["GHSA-c59q-g84q-2gj5","CVE-2026-82392"],"summary":"pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph","severity":"high"},{"id":"BREW-pnpm@9-CVE-2026-82393","upstream":["GHSA-vq4v-j7r6-jq4m","CVE-2026-82393"],"summary":"pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install","severity":"high"}],"patched":[],"fixed_count":0},"analytics":{"install":{"30d":{"pnpm@9":7},"90d":{"pnpm@9":138},"365d":{"pnpm@9":1294,"pnpm@9 --HEAD":3}},"install_on_request":{"30d":{"pnpm@9":7},"90d":{"pnpm@9":138},"365d":{"pnpm@9":1294,"pnpm@9 --HEAD":3}},"build_error":{"30d":{"pnpm@9":0}}},
"generated_date":"2026-10-01"}
