All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-patches.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

pnpm Patches

pnpm's patching feature lets you modify third-party packages directly. Useful for applying fixes before upstream releases or customizing package behavior.

Creating a Patch

Step 1: Initialize Patch

pnpm patch <pkg>@<version>

# Example
pnpm patch express@4.18.2

This creates a temporary directory with the package source and outputs the path:

You can now edit the following folder: /tmp/abc123...

Step 2: Edit Files

Navigate to the temporary directory and make your changes:

cd /tmp/abc123...
# Edit files as needed

Step 3: Commit Patch

pnpm patch-commit <path-from-step-1>

# Example
pnpm patch-commit /tmp/abc123...

This creates a .patch file in patches/ and records it in pnpm-workspace.yaml:

patches/
└── express@4.18.2.patch
patchedDependencies:
  express@4.18.2: patches/express@4.18.2.patch

patchedDependencies (like all pnpm settings) now lives in pnpm-workspace.yaml, not the package.json#pnpm field.

Patch File Format

Patches use standard unified diff format:

diff --git a/lib/router/index.js b/lib/router/index.js
index abc123..def456 100644
--- a/lib/router/index.js
+++ b/lib/router/index.js
@@ -100,6 +100,7 @@ function createRouter() {
   // Original code
-  const timeout = 30000;
+  const timeout = 60000; // Extended timeout
   return router;
 }

Managing Patches

List Patched Packages

pnpm list --depth=0
# Shows (patched) marker for patched packages

Update a Patch

# Edit existing patch
pnpm patch express@4.18.2

# After editing
pnpm patch-commit <path>

Remove a Patch

pnpm patch-remove <pkg>@<version>

# Example  
pnpm patch-remove express@4.18.2

Or manually:

  1. Delete the patch file from patches/
  2. Remove the entry from patchedDependencies in pnpm-workspace.yaml
  3. Run pnpm install

Patch Configuration

Multiple Packages / Workspaces

Patches are shared across the whole workspace from the root pnpm-workspace.yaml:

patchedDependencies:
  express@4.18.2: patches/express@4.18.2.patch
  lodash@4.17.21: patches/lodash@4.17.21.patch
  '@types/node@20.10.0': patches/@types__node@20.10.0.patch

A version-less key (express:) patches every installed version. All workspace packages using a matching version get the patch.

Patches from a config dependency

Patch files can live inside a shared config dependency and be referenced by path:

configDependencies:
  my-patches: '1.0.0'
patchedDependencies:
  react: node_modules/.pnpm-config/my-patches/react.patch

allowUnusedPatches

allowUnusedPatches: true   # don't fail when a listed patch wasn't applied

ignorePatchFailures was removed in v11. A patch that fails to apply now always throws. When several patches are grouped, all errors are reported together at the end.

Best Practices

  1. Version specificity: Patches are tied to exact versions. Update patches when upgrading dependencies.

  2. Document patches: Add comments explaining why the patch exists:

    # In patches/README.md
    ## express@4.18.2.patch
    Fixes timeout issue. PR pending: https://github.com/expressjs/express/pull/1234
  3. Minimize patches: Keep patches small and focused. Large patches are hard to maintain.

  4. Track upstream: Note upstream issues/PRs so you can remove patches when fixed.

  5. Test patches: Ensure patched code works correctly in your use case.

Troubleshooting

Patch fails to apply

ERR_PNPM_PATCH_FAILED  Cannot apply patch

The package version changed. Recreate the patch:

pnpm patch-remove express@4.18.2
pnpm patch express@4.18.2
# Reapply changes
pnpm patch-commit <path>

Patch not applied

Ensure:

  1. Version in patchedDependencies matches installed version exactly
  2. Run pnpm install after adding patch configuration
<!-- Source references: - https://pnpm.io/cli/patch - https://pnpm.io/cli/patch-commit - https://pnpm.io/config-dependencies -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.