# Socket Weekly: pnpm 11 Tightens Supply Chain Defaults, Critical vm2…

Canonical: https://brew.new/browse/templates/email/pt1_k97gz578fyrytmzejchkck80xd8e4a3y

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: pnpm 11 Tightens Supply Chain Defaults, Critical vm2…](https://cdn.brew.new/email-preview-7eb6f0ea3315efc3-tracking_r57y10n23qabbw67r7h0zhyt7s8dtbzc-1789015374083.png)

## Email content

socket-weekly-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies

pnpm 11 tightens JavaScript supply chain security defaults. Minimum Release Age was already available as an opt-in setting, but pnpm 11 makes 24 hours the default, alongside blocking exotic subdependencies and a new Allow Builds model for controlling dependency build scripts. The new defaults target exactly the conditions that make modern package compromises move fast: newly published malicious versions, install-time execution, and hidden dependency sources. Package managers are increasingly where supply chain security decisions get enforced, and pnpm 11 is one example of how they're responding to the nonstop stream of attacks on the ecosystem.

MORE NEWS

Critical vm2 Sandbox Escape Lets Untrusted JavaScript Run OS Commands

A critical sandbox escape in vm2 (CVE-2026-26956) lets attacker-controlled JavaScript break isolation, access the host Node.js process, and run arbitrary OS commands. Our testing found the issue affects 66 vm2 releases, broader than the advisory's listed range, and a free Certified Patch is available for teams that can't immediately upgrade.

fsnotify Maintainer Dispute Sparks Supply Chain Concerns

A maintainer access dispute in fsnotify, a Go library used by 321k projects for cross-platform file notifications, raised supply chain concerns this week after contributors were removed from the GitHub org and a deleted X post fueled takeover speculation. Although no code was compromised, governance ambiguity in this low-level dependency was enough to send users checking release history, watching forks, and asking whether routine updates were still safe.

MORE WORTH READING

OpenJS Foundation Security Update: Q1 2026

5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer

Behind the Scenes Hardening Firefox with Claude Mythos Preview

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Scaling Trusted Access for Cyber with GPT‑5.5 and GPT‑5.5‑Cyber

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97gz578fyrytmzejchkck80xd8e4a3y)

[Browse email designs](https://brew.new/browse/templates)
