- Added experimental `nodeLinker: { type: "loaded" }` with direct loading from the content‑addressable store and new `nodeLinker.excluded` option.
- Lockfile now records resolution settings via `lockfile.includeResolutionSettings` and verifies config dependencies against registries, enhancing reproducibility and security.
- Implemented several security fixes: blocked path‑traversal writes, enforced integrity and signature checks, rejected oversized metadata, and tightened lockfile validation.