socket-dev · Crawled Jul 8, 2026
pnpm 11.10 Hardens Registry Authentication to Block Token Redirection
Read original article ↗AI Summary
The pnpm 11.10 release introduces security enhancements to prevent registry token redirection attacks in the npm ecosystem. A new _auth configuration ensures registry credentials are bound to their intended registry URL, preventing malicious project files from redirecting valid tokens to attacker-controlled hosts. This update mitigates supply chain risks by limiting the privileges of repository-controlled files and hardening authentication mechanisms.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.