pnpm 12.9.1 moves its WebContainer build out, shrinking the package from 55 MB to 4 MB
The pnpm package manager released version 12.9.1 on 3 October, a patch release whose most visible effect is on its own size.
Back to 4 MB. The WebAssembly build that lets pnpm run in StackBlitz WebContainers now ships as a separate package, @pnpm/wasm. The pnpm and @pnpm/exe packages no longer include it, which brings their unpacked size back from about 55 MB to about 4 MB. Inside a WebContainer, users install @pnpm/wasm with npm to get the pnpm command. For everyone else, installing pnpm in CI images and on developer machines becomes a much smaller download again.
Provenance from GitLab works. pnpm publish with provenance from GitLab CI had been rejected by the npm registry with a 422 error. The provenance statement now includes the GitLab CI variables in invocation.parameters, as npm's own client does.
Other fixes.
pnpm audit signaturesnow uses the TLS settings of the redirect target when a registry redirects its signing-keys request, for example to registry.npmjs.org, so acafilescoped to a private registry no longer breaks the redirected request.pnpm install --frozen-lockfileno longer rejects an up-to-date lockfile when an injected workspace package uses a catalog entry inpeerDependencies.- The
[<since>]filter selector works again with Git 2.24 to 2.27; with Git older than 2.24 it fails with an error naming the required version. It also now detects changes in projects whose directory names contain non-ASCII characters, which used to be credited to the parent project, andchangedFilesIgnorePatternandtestPatternmatch such file names.
The older line. pnpm also published 11.28.4 the same day for users still on version 11.

What it means
Two of these fixes matter for supply-chain hygiene. Teams that publish from GitLab can now attach provenance with pnpm instead of switching to npm for the publish step, and teams verifying registry signatures behind a private registry no longer see a TLS failure masquerading as a verification problem. The size fix is the one most users will notice first, in faster CI image builds.