All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-overrides.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

pnpm Overrides

Overrides let you force specific versions of packages, including transitive dependencies. Useful for fixing security vulnerabilities or compatibility issues.

Basic Syntax

Define overrides in pnpm-workspace.yaml. They can only be set at the root of the project.

The pnpm.overrides field in package.json is no longer read (pnpm no longer reads any settings from package.json#pnpm). Move overrides to pnpm-workspace.yaml.

packages:
  - 'packages/*'

overrides:
  # Override all versions of a package
  lodash: ^4.17.21

  # Override specific version range
  "foo@^1.0.0": ^1.2.3

  # Override nested dependency (only zoo inside qar@1)
  "qar@1>zoo": "2"

  # Override to different package
  "underscore": "npm:lodash@^4.17.21"

  # Reference a catalog so the version stays in sync
  "react": "catalog:"

Override Patterns

Override all instances

overrides:
  lodash: ^4.17.21

Forces all lodash installations to use ^4.17.21.

Override specific parent version

overrides:
  "foo@^1.0.0": ^1.2.3

Only override foo when the requested version matches ^1.0.0.

Override nested dependency

overrides:
  "express>cookie": ^0.6.0
  "foo@1.x>bar@^2.0.0>qux": ^1.0.0

Override cookie only when it's a dependency of express.

Replace with different package

overrides:
  # Replace underscore with lodash
  "underscore": "npm:lodash@^4.17.21"
  
  # Use local file
  "some-pkg": "file:./local-pkg"
  
  # Use git
  "some-pkg": "github:user/repo#commit"

Remove a dependency

overrides:
  "unwanted-pkg": "-"
  "foo@1.0.0>bar": "-"   # great for skipping unused optionalDependencies

The - removes the package entirely.

Override peer dependencies

Overrides also apply to peerDependencies:

overrides:
  "react-dom>react": "18.1.0"
  • Semver ranges, workspace:, and catalog: keep the entry as a peer dependency.
  • Non-range specifiers (link:, file:) move it into dependencies.
  • - removes the peer dependency entirely.

Common Use Cases

Security Fix

Force patched version of vulnerable package:

overrides:
  # Fix CVE in transitive dependency
  "minimist": "^1.2.6"
  "json5": "^2.2.3"

Deduplicate Dependencies

Force single version when multiple are installed:

overrides:
  "react": "^18.2.0"
  "react-dom": "^18.2.0"

Fix Peer Dependency Issues

overrides:
  "@types/react": "^18.2.0"

Replace Deprecated Package

overrides:
  "request": "npm:@cypress/request@^3.0.0"

Hooks Alternative

For more complex scenarios, use .pnpmfile.mjs:

function readPackage(pkg, context) {
  // Override dependency version
  if (pkg.dependencies?.lodash) {
    pkg.dependencies.lodash = '^4.17.21'
  }

  // Add missing peer dependency
  if (pkg.name === 'some-package') {
    pkg.peerDependencies = {
      ...pkg.peerDependencies,
      react: '*'
    }
  }

  return pkg
}

export const hooks = {
  readPackage
}

Or extend a manifest declaratively with packageExtensions (no JS needed):

packageExtensions:
  react-redux:
    peerDependencies:
      react-dom: '*'

Overrides vs Catalogs

Feature Overrides Catalogs
Affects All dependencies (including transitive) Direct dependencies only
Usage Automatic Explicit catalog: reference
Purpose Force versions, fix issues Version management
Granularity Can target specific parents Package-wide only

Debugging

Check which version is resolved:

# See resolved versions
pnpm why lodash

# List all versions
pnpm list lodash --depth=Infinity
<!-- Source references: - https://pnpm.io/settings#overrides - https://pnpm.io/settings#packageextensions - https://pnpm.io/pnpmfile -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.