The action no longer installs pnpm through npm. It downloads pnpm's self-contained release binary for the runner's platform straight from pnpm's GitHub releases, verifies it against the SHA-256 digest GitHub publishes for the asset, and puts it on PATH. No Node.js, no npm, no @pnpm/exe, no self-update round-trip.
That also makes the action immune to broken npm artifacts. pnpm 11.13.0's @pnpm/exe build shipped without its platform binary, which made v1 install a placeholder file that failed later with This: not found and exit code 127. The GitHub release binary for that same version is fine, so v2 installs it correctly. v2 additionally verifies the install by running pnpm --version and comparing it against the requested version, so a bad artifact fails immediately with a clear message instead of surfacing as a confusing error in a later step.
Breaking changes
pnpm v11 or newer is required. v1 could set up pnpm 10 via pnpm self-update; v2 rejects anything below v11 with an explanatory error. The action is built around pnpm's self-contained release binaries and the pnpm runtime command, both of which arrived in v11.
If you need pnpm 10 or older, use pnpm/action-setup instead.
The bin-dest output points somewhere new. It was ~/setup-pnpm/node_modules/.bin/bin; it is now ~/setup-pnpm (the dest directory itself). Workflows that read the output are unaffected — it still names the directory holding pnpm — but anything that hardcoded the old path needs updating.
cache-hit is stricter. It is now true only on an exact key match. v1 reported true for any restore. This matches what actions/cache means by cache-hit.
No inputs or outputs were removed or renamed.
What's new
- Flexible version specs.
versionaccepts an exact version (12.0.0-beta.4), a semver range (^12.0.0), or an npm dist-tag (next-12). It is still optional whenpackageManagerordevEngines.packageManageris set inpackage.json. - Partial store cache reuse. Cache restore now falls back to restore keys, so a single changed dependency no longer forces a full re-download of the store.
- New
tokeninput. Used for the GitHub release lookup, defaulting to${{ github.token }}so the low anonymous API rate limit doesn't apply. It rarely needs to be set. pnpx,pn, andpnxaliases are linked next to thepnpmbinary.
Upgrading
For most workflows the upgrade is the tag:
- - uses: pnpm/setup@v1
+ - uses: pnpm/setup@v2Check first that the pnpm version you install — via the version input, packageManager, or devEngines.packageManager — is v11 or newer.
One platform caveat: pnpm v11 publishes no binary for Intel macOS (darwin-x64). Use pnpm v12 or newer on Intel macOS runners.