pnpm@9 (deprecated)

Disable date: 2027-02-06

Install command:
brew install pnpm@9

Fast, disk space efficient package manager

https://pnpm.io/

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/pnpm@9.json

Formula code: pnpm@9.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
tahoe
sequoia
sonoma
ventura
macOS on
Intel
sonoma
ventura
Linux ARM64
x86_64

Current versions:

stable 9.15.9

Other versions:

pnpm@10 10.34.5 Fast, disk space efficient package manager

Keg-only

Depends on when building from source:

node 26.7.0 Open-source, cross-platform JavaScript runtime environment
pnpm requires a Node installation to function. You can install one with:
    brew install node

Known vulnerabilities in the current version:

GHSA-8cc4-rfj6-fhg4 (medium) pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect...
GHSA-2phv-j68v-wwqx (high) pnpm vulnerable to Command Injection via environment variable substitution
GHSA-7vhp-vf5g-r2fw (high) pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
GHSA-6pfh-p556-v868 (medium) pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
GHSA-6x96-7vc8-cm3p (medium) pnpm has Windows-specific tarball Path Traversal
GHSA-xpqm-wm3m-f34h (medium) pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
GHSA-m733-5w8f-5ggw (medium) pnpm has symlink traversal in file:/git dependencies
GHSA-v253-rj99-jwpq pnpm has Path Traversal via arbitrary file permission modification
GHSA-hg3w-7f8c-63hp pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
GHSA-p4xf-rf54-rj3x (medium) pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
GHSA-rxhj-4m44-96r4 (high) pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
GHSA-hwx4-2j3j-g496 (high) pnpm: Transitive dependency alias path traversal allows project path override via symlink replace...
GHSA-cjhr-43r9-cfmw pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
GHSA-q6j5-fjx5-2mc3 (medium) pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
GHSA-54hh-g5mx-jqcp (medium) pnpm: Unsafe default behavior breaks integrity check
GHSA-3qhv-2rgh-x77r (medium) pnpm: Repository config can expand victim environment secrets into registry requests before scrip...
GHSA-5wx6-mg75-v57r (high) pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
GHSA-gj8w-mvpf-x27x (high) pnpm: Repository-controlled configDependencies can select a pacquet native install engine
GHSA-w466-c33r-3gjp (high) pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-sele...
GHSA-4gxm-v5v7-fqc4 (medium) pnpm: Reserved bin name deletes PNPM_HOME during global remove
GHSA-72r4-9c5j-mj57 (high) pnpm: `patch-remove` could delete project-selected files outside the patches directory
GHSA-qrv3-253h-g69c (high) pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modu...
GHSA-fr4h-3cph-29xv (high) pnpm: Hoisted install imports lockfile alias outside node_modules

Data from Homebrew/advisory-database. Run brew vulns pnpm@9 for a live check.

Analytics:

30 days90 days365 days
Installs832041,442
Installs (--HEAD)004
Installs on Request832041,442
Installs on Request (--HEAD)004
Build Errors0