Repository navigation
Releases: pnpm/setup
Release list
v3.0.0
What's Changed
- fix!: include runid in cache key, restore freshest lockfile match by @poulet42 in #43
- feat!: automatically detect Node.js version files by @Neonsy in #49
- docs: add private registry authentication recipes by @zkochan in #61
- fix: avoid deprecated shell spawning for pnpm commands by @sebdanielsson in #52
- fix: require-lockfile no longer accepts a lockfile pnpm will not use by @zkochan in #60
New Contributors
Full Changelog: v2.1.0...v3.0.0
v2.1.0
What's Changed
- fix: restore cache before installing runtime by @Stanzilla in #39
- feat: install multiple runtimes from devEngines.runtime by @BlankParticle in #32
- perf: cache pnpm's lockfile verification results by @zkochan in #30
- feat: add
working-directory, deprecatingpackage-json-fileby @haines in #27 - feat: add a
require-lockfileinput by @sebdanielsson in #23 - ci: update dependencies with pnpm/update instead of Dependabot by @zkochan in #41
- chore: update dependencies by @github-actions[bot] in #42
New Contributors
- @Stanzilla made their first contribution in #39
- @BlankParticle made their first contribution in #32
- @haines made their first contribution in #27
- @sebdanielsson made their first contribution in #23
- @github-actions[bot] made their first contribution in #42
Full Changelog: v2.0.2...v2.1.0
v2.0.2
What's Changed
- feat: install pnpm from the npm registry, verified against npm's signature by @zkochan in #24
- fix: keep the installed runtime authoritative against context-aware shims by @zkochan in #25
Full Changelog: v2.0.1...v2.0.2
v2.0.1
What's Changed
- fix: normalize Windows cache store paths by @zkochan in #22
- docs(README): bump versions (node, action/setup) by @urban-adeininger in #20
New Contributors
- @urban-adeininger made their first contribution in #20
Full Changelog: v2.0.0...v2.0.1
v2.0.0
The action no longer installs pnpm through npm. It downloads pnpm's self-contained release binary for the runner's platform straight from pnpm's GitHub releases, verifies it against the SHA-256 digest GitHub publishes for the asset, and puts it on PATH. No Node.js, no npm, no @pnpm/exe, no self-update round-trip.
That also makes the action immune to broken npm artifacts. pnpm 11.13.0's @pnpm/exe build shipped without its platform binary, which made v1 install a placeholder file that failed later with This: not found and exit code 127. The GitHub release binary for that same version is fine, so v2 installs it correctly. v2 additionally verifies the install by running pnpm --version and comparing it against the requested version, so a bad artifact fails immediately with a clear message instead of surfacing as a confusing error in a later step.
Breaking changes
pnpm v11 or newer is required. v1 could set up pnpm 10 via pnpm self-update; v2 rejects anything below v11 with an explanatory error. The action is built around pnpm's self-contained release binaries and the pnpm runtime command, both of which arrived in v11.
If you need pnpm 10 or older, use pnpm/action-setup instead.
The bin-dest output points somewhere new. It was ~/setup-pnpm/node_modules/.bin/bin; it is now ~/setup-pnpm (the dest directory itself). Workflows that read the output are unaffected — it still names the directory holding pnpm — but anything that hardcoded the old path needs updating.
cache-hit is stricter. It is now true only on an exact key match. v1 reported true for any restore. This matches what actions/cache means by cache-hit.
No inputs or outputs were removed or renamed.
What's new
- Flexible version specs.
versionaccepts an exact version (12.0.0-beta.4), a semver range (^12.0.0), or an npm dist-tag (next-12). It is still optional whenpackageManagerordevEngines.packageManageris set inpackage.json. - Partial store cache reuse. Cache restore now falls back to restore keys, so a single changed dependency no longer forces a full re-download of the store.
- New
tokeninput. Used for the GitHub release lookup, defaulting to${{ github.token }}so the low anonymous API rate limit doesn't apply. It rarely needs to be set. pnpx,pn, andpnxaliases are linked next to thepnpmbinary.
Upgrading
For most workflows the upgrade is the tag:
- - uses: pnpm/setup@v1
+ - uses: pnpm/setup@v2Check first that the pnpm version you install — via the version input, packageManager, or devEngines.packageManager — is v11 or newer.
One platform caveat: pnpm v11 publishes no binary for Intel macOS (darwin-x64). Use pnpm v12 or newer on Intel macOS runners.
v1
Ready for production use.
v0.0.0
Initial release