-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Security: pnpm/pnpm
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
No-script global cache poisoning via overrides / `ignore-scripts` evasionGHSA-vm32-9rqf-rh3r published
Dec 10, 2024 by zkochanModerate -
The md5 path shortening function causes packet paths to coincide, which causes indirect packet overwritingGHSA-8cc4-rfj6-fhg4 published
Apr 23, 2025 by zkochanModerate -
pnpm incorrectly parses tar archives relative to specificationGHSA-5r98-f33j-g8h7 published
Aug 1, 2023 by zkochanHigh