pnpm 11.0 is out, and the change I care about is a default. The minimumReleaseAge setting is now 1440 minutes: a version published to the registry less than a day ago will not be installed unless you ask for it explicitly. Alongside it, blockExoticSubdeps is on by default, so a transitive dependency that points at a git repository or a tarball URL instead of the registry is rejected. The release also requires Node.js 22 or newer, consolidates the build-script allowlist into a single allowBuilds setting, and limits .npmrc to authentication, with pnpm's own settings moving to a dedicated config file.
I think the one-day delay is the first time a mainstream package manager has said plainly what the supply chain incidents of the last two years have been saying: installing the latest version the minute it appears is a security anti-pattern. Nearly every malicious package in those incidents was published, discovered, and pulled within hours. A one-day cooling-off period means most of them never reach a developer's machine or a build.
The cost is tiny. A fix you need today can be requested by name. Everything else can wait a day, and nobody will notice.
My view is that teams should not wait for npm and Yarn to catch up. The same policy can be set in both today, in the lockfile discipline and in the install flags, and it should be.
Does your team have a minimum age for a dependency before it is allowed into a build?
Photo source: https://photos.robertstowe.com/flowers

