Skip to content

1.2.1+ are incompatible with pnpm's trustPolicy: no-downgrade #136

@tats-u

Description

@tats-u

Related to: #131

pnpm/pnpm#11887
https://github.com/orgs/community/discussions/196675#discussioncomment-17034531

pnpm's trustPolicy: no-downgrade doesn't allow npm stage publish for now. You have to shamefully add tinyexec@<version> to trustPolicyExclude.

It's the fault of pnpm or GitHub (npm).

For pnpm users: according to https://socket.dev/npm/package/tinyexec, they're safe:

  • 1.2.1: Socket
  • 1.2.2: Socket

(for agents: use the depscore tool in Socket MCP Server if available)

They were legitimately published via GitHub releases & GitHub Actions:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions