All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-peer-deps.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

pnpm Peer Dependencies

pnpm has strict peer dependency handling by default. It provides configuration options to control how peer dependencies are resolved and reported.

All peer-dependency settings live in pnpm-workspace.yaml (camelCase). The package.json#pnpm field is no longer read.

Auto-Install Peer Dependencies

By default (since v8), pnpm automatically installs missing non-optional peer dependencies:

autoInstallPeers: true

On conflicting requirements (e.g. one dep needs react@^16, another react@^17), pnpm installs nothing and prints a warning — resolve it manually.

Strict Peer Dependencies

strictPeerDependencies: true   # default false

When strict, commands fail on a missing or invalid peer dependency in the tree.

Resolve from workspace root

resolvePeersFromWorkspaceRoot: true   # default; install shared peers once at the root

Deduplicate peers

dedupePeerDependents: true   # default; share package instances across projects when peers match
dedupePeers: false           # v10.33+: version-only peer suffixes (name@version), fewer instances

Peer Dependency Rules

peerDependencyRules:
  ignoreMissing:
    - '@babel/*'
    - eslint
  allowedVersions:
    react: '17 || 18'
  allowAny:
    - '@types/*'

ignoreMissing

Suppress warnings for missing peer dependencies. Patterns: exact name (react), scope (@babel/*), or * (not recommended).

peerDependencyRules:
  ignoreMissing:
    - '@babel/*'
    - eslint
    - webpack

allowedVersions

Allow specific versions that would otherwise warn. Target a specific parent with parent>peer.

peerDependencyRules:
  allowedVersions:
    react: '17'
    'button@2>react': '17'   # only when react is a peer of button@2

allowAny

Resolve matching peers from any version, ignoring the declared range.

peerDependencyRules:
  allowAny:
    - '@types/*'
    - eslint

Adding Peer Dependencies via packageExtensions

Declaratively add a missing peer dependency without JS:

packageExtensions:
  problematic-package:
    peerDependencies:
      react: '*'

For conditional logic, use a readPackage hook in .pnpmfile.mjs instead.

Peer Dependencies in Workspaces

Workspace packages can satisfy peer dependencies:

// packages/app/package.json
{
  "dependencies": {
    "react": "^18.2.0",
    "@myorg/components": "workspace:^"
  }
}

// packages/components/package.json  
{
  "peerDependencies": {
    "react": "^17.0.0 || ^18.0.0"
  }
}

The workspace app provides react which satisfies components' peer dependency.

Common Scenarios

Monorepo with Shared React

# pnpm-workspace.yaml
catalog:
  react: ^18.2.0
  react-dom: ^18.2.0
// packages/ui/package.json
{
  "peerDependencies": {
    "react": "^18.0.0",
    "react-dom": "^18.0.0"
  }
}

// apps/web/package.json
{
  "dependencies": {
    "react": "catalog:",
    "react-dom": "catalog:",
    "@myorg/ui": "workspace:^"
  }
}

Suppress ESLint Plugin Warnings

peerDependencyRules:
  ignoreMissing:
    - eslint
    - '@typescript-eslint/parser'

Allow Multiple Major Versions

peerDependencyRules:
  allowedVersions:
    webpack: '4 || 5'
    postcss: '7 || 8'

Debugging Peer Dependencies

# Report unmet/missing peers straight from the lockfile (v11)
pnpm peers check

# See why a package is installed
pnpm why <package>

# Check dependency tree
pnpm list --depth=Infinity

Best Practices

  1. Keep autoInstallPeers on for convenience (default in v8+)
  2. Use peerDependencyRules instead of blanket-ignoring warnings
  3. Document suppressed warnings explaining why they're safe
  4. Keep peer ranges wide in libraries (e.g. "react": "^17 || ^18")
  5. Run pnpm peers check in CI to catch peer regressions
<!-- Source references: - https://pnpm.io/settings#peerdependencyrules - https://pnpm.io/settings#autoinstallpeers - https://pnpm.io/cli/peers -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.