BetaWeekly digests are a beta — we're trying something new. Feedback welcome.
Turborepo patches two CVEs as pnpm lands dedupe and relocatable modules
September 21–27, 2026
Turborepo shipped a security release patching two vulnerabilities in js-yaml and its docs toolchain while reworking remote-cache behavior, and pnpm rolled out automatic dependency deduplication, relocatable node_modules, and repo-config-aware Node shims across three releases.
Turborepo hardens the supply chain
Turborepo's week was dominated by a security patch and a run of resilience work around the remote cache. The headline fix upgraded js-yaml to close CVE-2026-84375 and bumped Next.js in docs and factory builds for CVE-2026-94545, with the js-yaml update also landing on the canary line alongside lockfile-hash stabilization for pnpm workspaces. Teams auditing their build dependencies should treat this as the release to pull forward.
The remote cache got noticeably more defensive. Turborepo now backs off artifact requests during outages, disables the cache after unrecoverable forbidden responses and shares concurrent token recovery so rate limiting doesn't strand parallel tasks, and stops tasks when the parent process exits instead of leaving orphans behind. Signing now covers complete on-disk artifacts after local cache writes, closing a gap where partial artifacts could slip through.
Correctness fixes clustered around affected detection and file handling. Negated global dependencies are now respected in affected detection, root internal dependency changes are treated as global, gitignored files are properly ignored in boundaries, and affected task input globs are normalized rather than mangled. A fix for secondary go.work files Go reads for workspace members will matter to monorepos with Go packages.
The plumbing changes are quieter but useful: the turbo npm package now bundles documentation, versioned standalone archives are published with a working installer job, and curl | bash users finally get standalone installer URLs. After the long refactor that split run orchestration and task-graph crates out of turborepo-lib, the CLI is shedding legacy baggage while keeping the surface stable.
pnpm: dedupe by default, modules you can move
pnpm's three releases this week read as one arc toward less manual dependency wrangling. The centerpiece is automatic deduplication during install, which collapses compatible version ranges without a separate command, alongside relocatable node_modules, a --save-types flag for installing @types/* next to their packages, and catalog support for file: and link: protocols.
Later releases pulled features down to the JavaScript CLI and reconnected it to the repo. There's now a global node shim that follows .nvmrc and .node-version, pnpm install --allow-build and pnpm publish --publish-wait-timeout, plus automatic creation of pnpm-workspace.yaml from package.json's workspaces field — and --force no longer drags in optional deps built for other platforms. The 11.x line received a parallel backport of platform-ignore and peer-update settings with fixes across deploy, filtering, and hoisted nodeLinker setups, plus security patches for shell completion, Nix bin shims, and lifecycle scripts running inside a custom modulesDir.
Vitest steadies the test loop
Two Vitest fixes shipped for developers who live in the editor. The VS Code extension no longer crashes on the newest VS Code release, and it now tolerates unexpected coverage output while keeping a single scoped watcher. On the runner side, toMatchObject handles asymmetric matchers correctly again and spying Set.prototype.add no longer overflows the stack — a relief for jsdom 28+ users whose Request bodies carry Blobs.
Releases covered15
- Turborepo v2.11.5 patches CVE-2026-84375 and CVE-2026-94545 (opens in new tab)
- Turborepo v2.11.5-canary.3 patches js-yaml CVE and stabilizes pnpm lockfile hashes (opens in new tab)
- Turborepo v2.11.5-canary.1 fixes remote cache forbidden handling and negated global deps (opens in new tab)
- Turborepo v2.11.4 fixes affected detection for negated global dependencies (opens in new tab)
- Turborepo v2.11.3-canary.4 fixes affected detection for root dependency changes (opens in new tab)
- Turborepo v2.11.3-canary.3 fixes boundaries gitignore and prune tag order (opens in new tab)
- Turborepo v2.11.3 fixes affected task globs and boundaries gitignore handling (opens in new tab)
- Turborepo v2.11.5-canary.2 bundles docs in turbo npm package (opens in new tab)
- Turborepo v2.11.5-canary.4 publishes versioned standalone turbo archives (opens in new tab)
- Turborepo v2.11.5-canary.5 adds standalone installer URLs for curl | bash (opens in new tab)