Ad
 
Learn More

Login redirect creds is the Important line in pnpm 12.9

pnpm 12.9 is flagged Important as a security fix. The partner-break line is pnpm login forwarding credentials in the request body to another origin during redirects, not WebAssembly in StackBlitz.

Written by Watch Changelog Team

•2 min read

Login redirect creds is the Important line in pnpm 12.9

So pnpm put v12.9.0 on the feed, dated October 2, 2026. We flagged it Important as a security fix. Recency wants the calm opener: StackBlitz WebContainers now run the WebAssembly build, registries can set networkConcurrency, and pnpm install records every installed project in the store. Fine. Those are the lines people paste into a tooling channel when they skim a package-manager release.

The line that matters, to the best of my understanding, is one patch sentence under the feature list: pnpm login no longer forwards credentials in its request body to another origin during redirects. Login posts username and password (or the equivalent auth body) to a registry URL. If that request follows a cross-origin redirect, the body used to ride along. That is the partner ticket shape. Someone already thought "we only log into our private registry." Then a redirect hops to a different host, and the credential body is still attached.

That is why this patch is not optional for teams that run pnpm login against corporate registries, Verdaccio, Artifactory, or any registry that can 3xx. Scope is anyone who authenticates through pnpm login / pnpm adduser and whose registry (or a proxy in front of it) issues redirects. If every login is a straight 200 to a fixed origin you control and never redirects, this specific path is quieter. If partners share registry hostnames, use SSO gateways, or sit behind CDN/proxy redirects, treat credential isolation on the login POST as the reason 12.9 is not a feature bump you can skip.

What operators should check first is not the StackBlitz note on the release page. It is which developer machines and CI images still pin pnpm below 12.9 and still run interactive or scripted pnpm login against registries that redirect. Confirm whether login traffic goes through a corporate proxy, IdP bounce, or registry mirror that returns 301/302/307/308. After upgrade, expect the same login UX; the change is that a redirect no longer carries the credential body to the next origin.

The same release also carries the WebAssembly StackBlitz path, per-registry networkConcurrency, store project recording, and a long install/frozen-lockfile/optional-deps patch train. Those matter for DX and monorepo speed. They are not the hero. The hero is login no longer shipping credentials across a redirect boundary.

I keep almost filing pnpm under "package manager minor, ignore until the lockfile format moves." Kind of the wrong habit when you sell into teams that treat pnpm login as the gate to a private registry and assume the password body stays on the host they typed. Tracking product change here means reading past the StackBlitz headline and asking which line changes a partner ticket. Let's say the talking point is not "12.9 ships WASM in WebContainers." It is pnpm login could forward credentials to another origin during redirects, and 12.9 closes that hole, then yes mention concurrency and store recording. We pull it into a uniform entry shape at /sources/pnpm.releases. Same JSON as everything else. Recency still wants the StackBlitz line. Recency is not the login redirect.

Official notes: pnpm 12.9.0. Tag: v12.9.0.