All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

SKILL.md

≈66 tokens always: the name and description. ≈1.2k when used: this file. ≈27k more on demand in 20 files.

pnpm is a fast, disk space efficient package manager. It uses a content-addressable store to deduplicate packages across all projects on a machine, and enforces strict dependency resolution by default, preventing phantom dependencies.

pnpm v12 is a Rust rewrite of v11: stable, and keeps v11's commands, flags, settings, and lockfile format — so most guidance here applies to both. A handful of v12 behaviors differ (git deps resolve via HTTPS, project-aware global bins, other package managers, packageImportMethod: auto hardlinks first on Linux, --resolution-only removed) — see best-practices-migration.

Configuration model (important): pnpm settings live in pnpm-workspace.yaml (and the global config.yaml) using camelCase keys. .npmrc is used only for authentication/registry credentials, and the pnpm field of package.json is no longer read. When working in a pnpm project, check pnpm-workspace.yaml for settings/workspace structure and .npmrc only for auth. Always use --frozen-lockfile (or pnpm ci) in CI.

The skill is based on pnpm 12.x, generated at 2026-09-25. It covers v11+v12 behavior (config split, isolated global packages, allowBuilds, pmOnFail, global virtual store, native release management, workspace task orchestration, and experimental Python/Cargo support) where current docs describe them.

Core

Topic Description Reference
CLI Commands install/add/remove/update, run, dlx/pnx, workspace, runtime, publishing (version, view, sbom, stage) core-cli
Configuration pnpm-workspace.yaml settings (camelCase), global config.yaml, packageConfigs, .npmrc auth core-config
Workspaces Monorepo support: filtering, workspace protocol, shared lockfile, packageConfigs core-workspaces
Store Content-addressable store, virtual store, node linker modes, frozen/read-only store core-store

Features

Topic Description Reference
Catalogs Centralized dependency versions; catalogMode, catalog: in overrides features-catalogs
Overrides Force versions (incl. transitive & peer deps); packageExtensions features-overrides
Patches Modify third-party packages; patchedDependencies in pnpm-workspace.yaml features-patches
Aliases Install under custom names (npm:) and registry aliases (namedRegistries) features-aliases
Hooks .pnpmfile.mjs hooks (readPackage, updateConfig, beforePacking), finders, resolvers/fetchers features-hooks
Peer Dependencies Auto-install, strict mode, rules, dedupePeers, peers check features-peer-deps
Config Dependencies Share hooks/settings/catalogs/patches across repos via configDependencies features-config-dependencies
Global Virtual Store & Shims Shared node_modules, git-worktree multi-agent setups, isolated global packages, project-aware bins, other package managers features-global-virtual-store
Supply-Chain Security Build approval (allowBuilds), minimumReleaseAge, trustPolicy, lockfile integrity features-supply-chain-security
Task Orchestration Cross-project task graphs (tasks/dependsOn), concurrency groups, priority, pnpm pipeline features-task-orchestration
Release Management Native versioning: pnpm change/version -r/lane, lanes, epics, fixed groups features-versioning
Multi-Ecosystem Python (pypi:) and Cargo (crate:) dependencies alongside npm (experimental) features-multi-ecosystem

Best Practices

Topic Description Reference
CI/CD Setup GitHub Actions, GitLab, Docker, pnpm ci, store caching, frozen lockfiles best-practices-ci
Migration npm/Yarn → pnpm, phantom deps, and pnpm v10 → v11 → v12 upgrade notes best-practices-migration
Performance Install optimizations, allowBuilds, global virtual store, workspace parallelization best-practices-performance

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.