All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencescore-config.md

≈1.9k tokens on demand. Your agent reads this file only when SKILL.md points to it.

pnpm Configuration

pnpm settings are split into two categories. Knowing where each goes is the single most important config concept in current pnpm:

Category Stored in Format
All pnpm/install settings (nodeLinker, hoistPattern, autoInstallPeers, overrides, catalog, …) pnpm-workspace.yaml (project) and config.yaml (global) YAML, camelCase keys
Auth & registry credentials (_authToken, cert, key, …) .npmrc (project, gitignored) and global rc INI

Important changes: pnpm no longer reads settings from the pnpm field of package.json, and .npmrc is now used only for authentication/registry credentials. Everything else belongs in pnpm-workspace.yaml. Keys in YAML are camelCase (e.g. nodeLinker), not the kebab-case used by old .npmrc files.

The upstream settings reference is now split into pages by area — settings/build, settings/cli, settings/dependency-resolution, settings/network, settings/node-modules, settings/store, settings/peer-dependencies, settings/versioning, settings/other — but they are all the same camelCase keys in pnpm-workspace.yaml.

pnpm-workspace.yaml (primary config)

Place at the workspace/project root. Even a single-package project uses this file for pnpm settings.

# Workspace packages (omit for a single-package repo)
packages:
  - 'packages/*'
  - 'apps/*'
  - '!**/test/**'

# Common install settings (camelCase)
nodeLinker: isolated          # isolated (default) | hoisted | pnp
autoInstallPeers: true
strictPeerDependencies: false
savePrefix: '^'
saveExact: false
hoistPattern:
  - '*eslint*'
  - '*babel*'
publicHoistPattern: []
shamefullyHoist: false
dedupeDirectDeps: false
resolutionMode: highest       # highest | time-based | lowest-direct

# Centralized version management
catalog:
  react: ^18.2.0

# Force dependency versions (root only)
overrides:
  lodash: ^4.17.21
  'foo@^1.0.0>bar': ^2.0.0

# Extend/patch broken package manifests
packageExtensions:
  react-redux:
    peerDependencies:
      react-dom: '*'

# Peer dependency rules
peerDependencyRules:
  ignoreMissing:
    - '@babel/*'
  allowedVersions:
    react: '17 || 18'

Global configuration (config.yaml)

User-level non-auth settings live in a global YAML config.yaml:

  • $XDG_CONFIG_HOME/pnpm/config.yaml (if set)
  • Linux: ~/.config/pnpm/config.yaml
  • macOS: ~/Library/Preferences/pnpm/config.yaml
  • Windows: ~/AppData/Local/pnpm/config/config.yaml

The companion global rc file (same directory, named rc) holds only registry/auth settings.

Per-project settings in a workspace (packageConfigs)

There are no per-subproject .npmrc files anymore. Set per-package config via packageConfigs in the root pnpm-workspace.yaml:

packageConfigs:
  # Map form: keyed by package name
  project-1:
    saveExact: true
  project-2:
    savePrefix: '~'
  # Array form: pattern-matched rules
  # - match: ['project-1', 'project-2']
  #   modulesDir: node_modules
  #   saveExact: true

.npmrc — authentication only

Keep auth tokens out of the repo (gitignore the project .npmrc). Auth files, highest priority first:

  1. <workspace root>/.npmrc (project, gitignored)
  2. <pnpm config>/auth.ini (written by pnpm login)
  3. ~/.npmrc (fallback for npm compatibility)
//registry.npmjs.org/:_authToken=${NPM_TOKEN}
@myorg:registry=https://npm.myorg.com/
//npm.myorg.com/:_authToken=${MYORG_TOKEN}

Structured _auth (v11.10+, for CI)

An alternative to many //host/:_authToken=… lines, keyed by registry URL. Honored only from the global config.yaml and the pnpm_config__auth (or PNPM_CONFIG__AUTH) env var — ignored in a project .npmrc/pnpm-workspace.yaml, so a checked-out repo can never supply auth. pnpm login writes this shape since v12.1.

_auth:
  https://registry.npmjs.org:
    "@":         { authToken: npm-token }   # @ = registry-wide/default
    "@org":      { authToken: org-token }   # scope-bound on the same host
export pnpm_config__auth='{"https://registry.npmjs.org":{"@":{"authToken":"npm-token"}}}'

Configure registries themselves (non-secret) in pnpm-workspace.yaml:

registries:
  default: https://registry.npmjs.org/
  '@my-org': https://private.example.com/
# Named registry aliases usable as a prefix, e.g. `pnpm add work:@corp/lib`
namedRegistries:
  work: https://npm.work.example.com/

Security: since v11, env-variable expansion is disabled for registry/proxy URLs and credential keys in the project .npmrc (to stop a malicious repo from leaking secrets). Put dynamic-token lines in the user-level auth file instead.

The pnpm config command

# Writes to global config.yaml / rc by default
pnpm config set nodeVersion 22.0.0
pnpm config set --location=project nodeVersion 22.0.0   # writes pnpm-workspace.yaml

# JSON values create arrays/objects
pnpm config set --location=project --json allowBuilds '{"react": true}'

# get/list print JSON (no longer INI) since v11
pnpm config get nodeLinker
pnpm config get 'allowBuilds.react'
pnpm config list

Environment variables

Use pnpm_config_* (or PNPM_CONFIG_*). pnpm no longer reads npm_config_*.

pnpm_config_save_exact=true pnpm add foo

Notable settings that changed names

Old (removed) Replacement Notes
onlyBuiltDependencies, neverBuiltDependencies, ignoredBuiltDependencies, onlyBuiltDependenciesFile allowBuilds: { name: true|false } Single map controlling build-script approval. See supply-chain-security.
managePackageManagerVersions, packageManagerStrict, packageManagerStrictVersion, COREPACK_ENABLE_STRICT pmOnFail: download|ignore|warn|error Behavior when running pnpm version ≠ declared one.
useNodeVersion devEngines.runtime (in package.json) Runtime pinning.
auditConfig.ignoreCves auditConfig.ignoreGhsas Use GHSA IDs.
allowNonAppliedPatches allowUnusedPatches ignorePatchFailures removed (patches now always throw).
package.json#pnpm field pnpm-workspace.yaml No longer read at all.

Package Manager / Runtime pinning (package.json)

{
  "packageManager": "pnpm@10.0.0",
  "devEngines": {
    "packageManager": { "name": "pnpm", "version": ">=11.0.0 <12.0.0", "onFail": "download" },
    "runtime": { "name": "node", "version": "22.x", "onFail": "download" }
  }
}

devEngines.packageManager supports ranges (resolved version stored in lockfile); packageManager requires an exact version. Override onFail without editing the manifest via pmOnFail / runtimeOnFail settings.

Key Points

  • All pnpm settings go in pnpm-workspace.yaml (camelCase) or global config.yaml; .npmrc is auth/registry only.
  • package.json#pnpm and npm_config_* env vars are no longer read.
  • Use packageConfigs for per-package settings inside a workspace.
  • Build-script approval is now one allowBuilds map; package-manager strictness is one pmOnFail setting.
  • pnpm config get/list output JSON, and --location=project writes to pnpm-workspace.yaml.
<!-- Source references: - https://pnpm.io/settings - https://pnpm.io/configuring - https://pnpm.io/npmrc - https://pnpm.io/pnpm-workspace_yaml - https://pnpm.io/package_json - https://pnpm.io/cli/config -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.