Skip to content

Build(deps): Bump @pnpm/pnpr from 0.1.0-alpha.8 to 0.1.0-alpha.11 - #2313

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pnpm/pnpr-0.1.0-alpha.11
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pnpm/pnpr-0.1.0-alpha.11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps @pnpm/pnpr from 0.1.0-alpha.8 to 0.1.0-alpha.11.

Release notes

Sourced from @​pnpm/pnpr's releases.

pnpr 0.1.0-alpha.11

pnpr now serves Cargo, Python, and container registries alongside npm, publishes across all of them in one transaction, and signs users in through OIDC.

Minor Changes

Cargo and Python registries

  • pnpr now serves Cargo and Python registries alongside npm from one instance. Hosted Cargo registries support cargo publish, cargo yank, and crate downloads. Hosted Python registries support pip install --index-url and twine upload. Upstream registries can proxy crates.io and PyPI with checksum verified downloads, and a router can combine sources from all three ecosystems.

    A registry that serves more than one ecosystem addresses them through /npm/, /cargo/, and /pypi/. A registry that serves only one ecosystem keeps serving packages at the root, so existing npm URLs still work. A /~<name>/ registry prefix must arrive with an unencoded ~.

    Registry names can be reused across ecosystems by grouping configuration under registries.npm, registries.cargo, registries.pypi, or registries.oci. Router sources and defaults resolve within their own ecosystem.

  • pnpm install now resolves Cargo and Python dependencies through the server configured in pnprServer. The client no longer fetches one sparse-index file per crate in the dependency graph, and no longer downloads a wheel to find out what it requires. If the server does not serve that resolution, pnpm resolves those dependencies locally.

  • pnpm install can install Cargo dependencies from the sparse registry configured by cargo.indexUrl. The generated Cargo.lock records that registry as the source of every crate.

  • cargo search works against a pnpr registry. It matches on crate name over the crates the registry hosts. Each result reports the crate's newest release that is not yanked, and a crate whose releases are all yanked reports its newest release.

Container images

  • pnpr now serves container images #14630. Declare a registry with ecosystem: oci, then push to it with docker, podman, or skopeo. The distribution API answers at /v2/ on the host root, and an image keeps its own name with no registry key in the path. Sign in with docker login, using a pnpr token as the password, or set oci.bearerAuth: true to hand clients short lived, repository scoped credentials instead.

    Ranged blob downloads, cross repository blob mounts, the referrers API, and paginated tag and repository listings are supported. Authorized users can delete unreferenced blobs, and a blob that a retained manifest still reaches stays protected while another publish is running. oci.maxBlobBytes and oci.maxManifestBytes cap what a client may upload.

  • pnpr can cache image pulls from Docker Hub and GHCR #14630. Upstream authentication supports repository scoped bearer tokens, and pnpr verifies every cached image by digest. A proxied download whose contents fail verification is aborted and stays out of the cache.

  • pnpr can resume OCI uploads across replicas when it keeps blobs in S3. Abandoned shared upload sessions expire at startup after 24 hours of inactivity. pnpr oci-gc --registry <name> collects old, unreferenced image blobs while registry writers are stopped, and --dry-run previews the cleanup.

Publishing and authentication

  • pnpr can now publish packages of more than one ecosystem in a single transaction. PUT /-/pnpr/v0/publish takes a batch whose entries each name their ecosystem, so a workspace that ships an npm package, a crate, and a Python distribution releases them together. OCI manifests can ride along in the same batch once their layers are uploaded #14630. A batch that fails a check publishes none of it, and a server that stops midway finishes the release on the next startup. An entry without an ecosystem is an npm publish document, the same one PUT /-/pnpm/v1/publish takes.

  • pnpr now supports OIDC browser sign in. Administrators can map provider subjects to registry users, and GitHub Actions can publish npm packages without a persistent registry token. Workload publishing is restricted to the packages you configure.

Builds and pipelines

  • pnpr can share Cargo compilation caches between CI and developers through sccache. Configure artifacts.compilerCaches to grant read and publication access separately. sccache can combine its local disk cache with pnpr's remote cache.

  • pnpr can store pnpm pipeline run reports. Turn it on with pipeline.enabled and configure each workspace's access and publish permissions under pipeline.workspaces. pnpm pipeline --report and --report-to submit run summaries and events, and pnpr answers with authenticated listing and detail endpoints and a web viewer. Records are kept with the hosted packages, so a run submitted through one replica is listed and served by every other.

Discovery and administration

  • pnpr can now serve browser registry UIs through an origin allowlist. Search supports pagination and maintainer filters, organization package listings are available, and authenticated publishers are recorded for discovery. Upstream discovery can be enabled per registry. Passing browse=true to the search APIs pages through the npm packages and Cargo crates a registry hosts, respecting its routing and package access rules.

    A registry directory endpoint lists the named registries, ecosystem endpoints, and routing order that the current user can see.

  • pnpr now reads every command line option from an environment variable when the flag is omitted. The variable is named after the flag with a PNPR_ prefix, so --public-url becomes PNPR_PUBLIC_URL and --disable-resolver becomes PNPR_DISABLE_RESOLVER. A flag given on the command line wins over its environment variable. Boolean flags accept true, 1, yes, on, false, 0, no, and off.

Patch Changes

... (truncated)

Commits
  • 19eb394 chore(release): pacquet 12.4.1, pnpr 0.1.0-alpha.11 (#14802)
  • 06db4f1 feat(pnpr): keep pipeline run records with the hosted packages (#14668)
  • 8760cfa fix(pnpr): approve a staged publish once across replicas (#14665)
  • f99d19d feat(pnpr): resolve Python projects through the install accelerator (#14613)
  • 614936e feat(pnpr): resolve Cargo dependencies through the install accelerator (#14607)
  • ea9b8f2 feat(pnpr): allow configuration through environment variables (#14434)
  • 98bab9f chore(release): pacquet 12.2.0, pnpr 0.1.0-alpha.10 (#14389)
  • 6d90c71 chore(release): 11.25.0, pacquet 12.1.0, pnpr 0.1.0-alpha.9 (#14306)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@pnpm/pnpr](https://github.com/pnpm/pnpm/tree/HEAD/pnpr/npm/pnpr) from 0.1.0-alpha.8 to 0.1.0-alpha.11.
- [Release notes](https://github.com/pnpm/pnpm/releases)
- [Commits](https://github.com/pnpm/pnpm/commits/pnpr@0.1.0-alpha.11/pnpr/npm/pnpr)

---
updated-dependencies:
- dependency-name: "@pnpm/pnpr"
  dependency-version: 0.1.0-alpha.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 20, 2026
@changeset-bot

changeset-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 193ddf0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​pnpm/​pnpr@​0.1.0-alpha.8 ⏵ 0.1.0-alpha.1172 -110010096 +190

View full report

@netlify

netlify Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for changesets ready!

Name Link
🔨 Latest commit 193ddf0
🔍 Latest deploy log https://app.netlify.com/projects/changesets/deploys/6ab0024835928e000841afac
😎 Deploy Preview https://deploy-preview-2313--changesets.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants