Skip to content

Releases: pnpm/setup

v3.0.0

Choose a tag to compare

@zkochan zkochan released this 20 Sep 21:03
Immutable release. Only release title and notes can be modified.
v3.0.0
fbda4c8

What's Changed

  • fix!: include runid in cache key, restore freshest lockfile match by @poulet42 in #43
  • feat!: automatically detect Node.js version files by @Neonsy in #49
  • docs: add private registry authentication recipes by @zkochan in #61
  • fix: avoid deprecated shell spawning for pnpm commands by @sebdanielsson in #52
  • fix: require-lockfile no longer accepts a lockfile pnpm will not use by @zkochan in #60

New Contributors

Full Changelog: v2.1.0...v3.0.0

v2.1.0

Choose a tag to compare

@zkochan zkochan released this 28 Aug 23:58
Immutable release. Only release title and notes can be modified.
v2.1.0
703c526

What's Changed

  • fix: restore cache before installing runtime by @Stanzilla in #39
  • feat: install multiple runtimes from devEngines.runtime by @BlankParticle in #32
  • perf: cache pnpm's lockfile verification results by @zkochan in #30
  • feat: add working-directory, deprecating package-json-file by @haines in #27
  • feat: add a require-lockfile input by @sebdanielsson in #23
  • ci: update dependencies with pnpm/update instead of Dependabot by @zkochan in #41
  • chore: update dependencies by @github-actions[bot] in #42

New Contributors

Full Changelog: v2.0.2...v2.1.0

v2.0.2

Choose a tag to compare

@zkochan zkochan released this 09 Aug 22:08
Immutable release. Only release title and notes can be modified.
v2.0.2
84cb39b

What's Changed

  • feat: install pnpm from the npm registry, verified against npm's signature by @zkochan in #24
  • fix: keep the installed runtime authoritative against context-aware shims by @zkochan in #25

Full Changelog: v2.0.1...v2.0.2

v2.0.1

Choose a tag to compare

@zkochan zkochan released this 07 Aug 10:45
Immutable release. Only release title and notes can be modified.
v2.0.1
4700d73

What's Changed

New Contributors

Full Changelog: v2.0.0...v2.0.1

v2.0.0

Choose a tag to compare

@zkochan zkochan released this 04 Aug 12:49
Immutable release. Only release title and notes can be modified.
v2.0.0
c9883cc

The action no longer installs pnpm through npm. It downloads pnpm's self-contained release binary for the runner's platform straight from pnpm's GitHub releases, verifies it against the SHA-256 digest GitHub publishes for the asset, and puts it on PATH. No Node.js, no npm, no @pnpm/exe, no self-update round-trip.

That also makes the action immune to broken npm artifacts. pnpm 11.13.0's @pnpm/exe build shipped without its platform binary, which made v1 install a placeholder file that failed later with This: not found and exit code 127. The GitHub release binary for that same version is fine, so v2 installs it correctly. v2 additionally verifies the install by running pnpm --version and comparing it against the requested version, so a bad artifact fails immediately with a clear message instead of surfacing as a confusing error in a later step.

Breaking changes

pnpm v11 or newer is required. v1 could set up pnpm 10 via pnpm self-update; v2 rejects anything below v11 with an explanatory error. The action is built around pnpm's self-contained release binaries and the pnpm runtime command, both of which arrived in v11.

If you need pnpm 10 or older, use pnpm/action-setup instead.

The bin-dest output points somewhere new. It was ~/setup-pnpm/node_modules/.bin/bin; it is now ~/setup-pnpm (the dest directory itself). Workflows that read the output are unaffected — it still names the directory holding pnpm — but anything that hardcoded the old path needs updating.

cache-hit is stricter. It is now true only on an exact key match. v1 reported true for any restore. This matches what actions/cache means by cache-hit.

No inputs or outputs were removed or renamed.

What's new

  • Flexible version specs. version accepts an exact version (12.0.0-beta.4), a semver range (^12.0.0), or an npm dist-tag (next-12). It is still optional when packageManager or devEngines.packageManager is set in package.json.
  • Partial store cache reuse. Cache restore now falls back to restore keys, so a single changed dependency no longer forces a full re-download of the store.
  • New token input. Used for the GitHub release lookup, defaulting to ${{ github.token }} so the low anonymous API rate limit doesn't apply. It rarely needs to be set.
  • pnpx, pn, and pnx aliases are linked next to the pnpm binary.

Upgrading

For most workflows the upgrade is the tag:

-      - uses: pnpm/setup@v1
+      - uses: pnpm/setup@v2

Check first that the pnpm version you install — via the version input, packageManager, or devEngines.packageManager — is v11 or newer.

One platform caveat: pnpm v11 publishes no binary for Intel macOS (darwin-x64). Use pnpm v12 or newer on Intel macOS runners.

v1

Choose a tag to compare

@zkochan zkochan released this 15 Jun 12:45
Immutable release. Only release title and notes can be modified.
v1.0.0
5d160c5

Ready for production use.

v0.0.0

v0.0.0 Pre-release
Pre-release

Choose a tag to compare

@zkochan zkochan released this 11 May 16:51
v0.0.0
7b64e33

Initial release