[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fikOAvU3Ta1grDcqGNw-Lfp0_bzaPPFcue7JMreEBLfE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"40c1b35b-75a3-4b1f-adb9-f1ba828d8519","pnpm-12-rust-rewrite-brings-supply-chain-security-improvements-to-package-management","7362590c-81ba-4868-83d6-9d310dec0901","pnpm 12 Rust Rewrite Brings Supply Chain Security Improvements to Package Management","The release of pnpm 12 highlights the ongoing importance of software supply chain security in developer tooling, introducing signed remote build artifacts and registry revisions to reduce the risk of tampered or malicious packages. While the performance gains are notable, the security enhancements are arguably more critical — unsigned or unverified build artifacts have historically been exploited to inject malicious code into widely-used packages. Organizations relying on Node.js ecosystems must actively evaluate and upgrade their package managers to versions that enforce artifact integrity. Failing to adopt tools with built-in supply chain protections leaves development pipelines vulnerable to dependency confusion, typosquatting, and build-time attacks. This release serves as a reminder that keeping developer tooling current is as essential as patching production systems.","**Immediate actions:**\n- Upgrade to pnpm 12 to take advantage of signed remote build artifacts and improved registry security controls.\n- Audit current package manager configurations across all CI\u002FCD pipelines to ensure artifact verification is enabled.\n\n**Long-term improvements:**\n- Enforce a policy requiring cryptographic signing and verification for all third-party build artifacts used in your pipelines.\n- Maintain an up-to-date inventory of all developer tools and package managers in use across the organization.\n- Implement a formal process for evaluating and adopting supply chain security features in developer tooling as they are released.\n\n**Detection measures:**\n- Integrate Software Composition Analysis (SCA) tools into CI\u002FCD pipelines to continuously monitor for vulnerable or tampered dependencies.\n- Enable logging and alerting on package registry interactions to detect anomalous or unexpected dependency resolutions.",[12,13,14,15,16,17,18],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SSDF (SP 800-218): Secure Software Development Framework","SLSA Framework: Supply-chain Levels for Software Artifacts","NIST CSF DE.CM-3: Personnel activity is monitored to detect cybersecurity events","OWASP Top 10 A06:2021 – Vulnerable and Outdated Components","published","2026-09-01T06:20:39.24107+00:00","2026-09-01T06:20:39.131+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fpnpm-12?utm_medium=feed","pnpm-12-s-rust-rewrite-cuts-install-times-by-up-to-90-dd093e","pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":34,"name":35,"slug":36,"description":37,"color":38},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]