All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-multi-ecosystem.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Multi-Ecosystem: Python & Cargo (v12.4.0+, experimental)

pnpm v12 can resolve and install Python and Rust/Cargo dependencies in the same pnpm install as npm packages. Both graphs share pnpm's connection budget, artifact verification, and content-addressable store; each keeps its own lockfile and requirement semantics. Settings and on-disk layout may still change.

Python

Enable in pnpm-workspace.yaml:

python:
  enabled: true

pnpm reads pyproject.toml, writes pylock.toml, and builds a .venv per project (a symlink into python-envs in the store; swapped atomically). It never touches a hand-made .venv.

pnpm add pypi:httpx            # -> httpx==<latest> in pyproject.toml
pnpm add pypi:httpx@0.28.1     # exact pin
pnpm add pypi:'httpx>=0.28'    # PEP 508 spec kept as written
pnpm add -D pypi:pytest
  • pnpm run/pnpm exec put .venv/bin (.venv/Scripts on Windows) on PATH, so scripts call pytest/ruff without activation.
  • --lockfile-only, --frozen-lockfile, --offline apply.
  • Local/workspace deps: declare in [tool.uv.sources] ({ workspace = true } or { path, editable }); a project with [build-system] is installed editable.
  • Build backends need approval under allowBuilds with Package URL keys: 'pkg:pypi/hatchling': true.
  • Indexes (v12.5.0+): declare via registries with ecosystem: pypi and route package names with packages patterns; python.indexUrl is no longer supported. Credentials go in .npmrc, matched by origin.
  • Multi-env locking: supportedArchitectures + python.versions: ['3.12','3.13'] locks wheels for each platform×interpreter.
  • Interpreter: auto-selected to satisfy each requires-python (prefers .python-version); downloads a python-build-standalone build if none fits (runtimeOnFail controls). Set python.executable to force one.
  • Key settings: python.enabled, python.executable, python.extras, python.groups (default ['dev']), python.versions, python.overrides, python.constraints. Per-project overrides in [tool.pnpm.python]. shared-environment = true under [tool.uv.workspace] shares one .venv across uv-workspace members.

Cargo

Enable in pnpm-workspace.yaml:

cargo:
  enabled: true
pnpm add crate:serde
pnpm add crate:serde@^1.0.200
  • pnpm reads the workspace Cargo.toml, writes a deterministic Cargo.lock, verifies each .crate against its checksum, unpacks into the store, and links a Cargo [directory source] under .pnpm/crates/crates-io. It writes a source-replacement block into .cargo/config.toml between # >>> pnpm-managed cargo sources >>> markers (your content outside is untouched).
  • cargo build then compiles offline against vendored sources; pnpm compiles nothing.
  • Crates are recorded only in Cargo.lock, never pnpm-lock.yaml. --lockfile-only/--frozen-lockfile/--offline apply.
  • Registry: declare a sparse index via registries with ecosystem: cargo (default crates.io); only one index per workspace. cargo.indexUrl is no longer supported. Auth reuses URL-scoped credentials plus CARGO_REGISTRY_TOKEN/$CARGO_HOME/credentials.toml.
  • Git deps and [patch]/[replace] overrides are honored and vendored for offline builds; workspaces with overrides/git deps require the default crates.io index.
  • Reuse Cargo build state across runs/worktrees with pnpm pipeline and tasks.<name>.cargoTargetDir.

pnpr acceleration

With pnprServer set, the server resolves the Python/Cargo graph so pnpm needn't download wheels/index files to discover requirements; it falls back to local resolution when the server doesn't answer for that ecosystem.

<!-- Source references: - https://pnpm.io/python - https://pnpm.io/cargo - https://pnpm.io/registries -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.