All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-config-dependencies.md

≈751 tokens on demand. Your agent reads this file only when SKILL.md points to it.

pnpm Config Dependencies

Config dependencies are npm packages that pnpm installs before all regular dependencies, so they can supply hooks, settings, patches, catalogs, and overrides that are reused across many repositories. They let you keep one shared "pnpm config" package and consume it everywhere.

Declaring config dependencies

They live in pnpm-workspace.yaml; their integrity is recorded in a dedicated env-lockfile document inside pnpm-lock.yaml.

configDependencies:
  my-configs: "1.0.0"

Add one with the --config flag:

pnpm add --config my-configs
pnpm add --config @myorg/pnpm-plugin-my-catalogs

Constraints

  • No regular dependencies. They may declare optionalDependencies, but only one level deep.
  • No lifecycle scripts (preinstall, postinstall, …).
  • optionalDependencies (used for platform-specific binaries, esbuild-style) must use exact versions — ranges/tags are rejected, keeping installs reproducible.

Auto-loaded plugins

A config dependency named pnpm-plugin-*, @*/pnpm-plugin-*, or @pnpm/plugin-* has its pnpmfile.mjs (or .cjs) loaded automatically from the package root.

Use cases

Import hook logic from a shared package

Because config deps install before the pnpmfile loads, you can import from them:

import { readPackage } from '.pnpm-config/my-hooks'

export const hooks = { readPackage }

Share settings & catalogs via updateConfig

A plugin can inject settings/catalog entries through the updateConfig hook:

export const hooks = {
  updateConfig(config) {
    config.catalogs.default ??= {}
    config.catalogs.default['is-odd'] = '1.0.0'
    return config
  }
}

After installing it as a config dependency, consumers can use the catalog:

pnpm add is-odd@catalog:   # installs is-odd@1.0.0, writes "is-odd": "catalog:"

Share patch files

Reference patches stored inside a config dependency:

configDependencies:
  my-patches: "1.0.0"
patchedDependencies:
  react: "node_modules/.pnpm-config/my-patches/react.patch"

Key Points

  • Centralize hooks, settings, catalogs, overrides, and patches in one package, consumed across repos.
  • Declared via configDependencies in pnpm-workspace.yaml; installed before regular deps.
  • No regular dependencies and no lifecycle scripts; optionalDependencies need exact versions.
  • pnpm-plugin-* / @pnpm/plugin-* packages auto-load their pnpmfile.
  • Pair with the updateConfig hook to push settings/catalogs into consuming projects.
<!-- Source references: - https://pnpm.io/config-dependencies - https://pnpm.io/pnpmfile#hooksupdateconfigconfig-config--promiseconfig -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.