Skip to content

PNPM Trust Policy: High-risk trust downgrade for "[email protected]" (possible package takeover) #19423

@ngrippa-bo

Description

@ngrippa-bo

What version of Tailwind CSS are you using?

v3.4.18

What build tool (or framework if it abstracts the build tool) are you using?

Nuxt

What version of Node.js are you using?

v24.11.1

What browser are you using?

N/A

What operating system are you using?

Windows

Describe your issue

  • Do not have a trust policy set in pnpm-workspace.yaml
  • pnpm add tailwindcss@3 (installs 3.4.18)
  • Enable trustPolicy: no-downgrade
  • Run pnpm update tailwindcss

 ERR_PNPM_TRUST_DOWNGRADE  High-risk trust downgrade for "[email protected]" (possible package takeover)

Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Earlier versions had provenance attestation, but this version has no trust evidence. A trust downgrade may indicate a supply chain incident.

Is this intendet, did you change something in your publishing process or does this indeed indicate a possible package takeover?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions