Home / npm packages / pnpm
Every file of pnpm@12.9.1 as published on npm: 446 files, 4.1 MB. Search them by exact text or regex, in milliseconds.
It uses: eval(), child_process, process.env, the fs module, http / https, fetch(), XMLHttpRequest, crypto, WebAssembly, install scripts.
| API | In pnpm | |
|---|---|---|
| eval() runs a string as JavaScript | Yes: 2 files e.g. dist/node_modules/node-gyp/gyp/pylib/gyp/generator/gypd.py | See the lines |
| new Function() builds a function from a string, like eval (with or without new) | No | Who does |
| child_process starts other programs | Yes: 6 files e.g. dist/node_modules/get-pnpm/lib/extractTarball.js | See the lines |
| process.env reads environment variables | Yes: 44 files e.g. dist/node_modules/tinyglobby/dist/index.cjs | See the lines |
| the fs module reads and writes files | Yes: 45 files e.g. dist/node_modules/fdir/dist/index.cjs | See the lines |
| http / https makes or serves HTTP requests with Node's own modules | Yes: 5 files e.g. dist/node_modules/undici/lib/dispatcher/client.js | See the lines |
| fetch() makes HTTP requests | Yes: 3 files e.g. dist/node_modules/node-gyp/lib/download.js | See the lines |
| XMLHttpRequest makes HTTP requests the old browser way | Yes: 1 file e.g. dist/node_modules/undici/lib/web/fetch/response.js | See the lines |
| crypto hashes, encrypts or makes random numbers | Yes: 11 files e.g. dist/node_modules/undici/lib/web/fetch/body.js | See the lines |
| WebAssembly loads WebAssembly code | Yes: 1 file e.g. dist/node_modules/undici/lib/dispatcher/client-h1.js | See the lines |
| document.cookie reads or writes browser cookies | No | Who does |
| install scripts runs a script when it's installed | Yes: 1 file e.g. package.json | See the lines |
Exact matches in the published files, so a mention in a comment counts too: open the lines to check.
Version 12.9.1 of pnpm publishes 446 files of source, 4.1 MB in all, not counting images, fonts and source maps.
Yes: pnpm calls eval() in 2 of its files.
Yes: pnpm uses child_process in 6 of its files.
Yes: pnpm has an install script in its package.json, so it runs code when it's installed.
The same engine answers over your documents and repositories: exact text and regex, every match counted, from your code or your AI agent.