All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-supply-chain-security.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

pnpm Supply-Chain Security

pnpm blocks several attack vectors by default. Agents installing dependencies must understand these, since installs can fail or prompt on them.

Build-script approval (allowBuilds)

By default pnpm does not run dependency lifecycle scripts (preinstall/install/postinstall). Packages must be explicitly approved. Approval lives in one allowBuilds map in pnpm-workspace.yaml.

allowBuilds:
  esbuild: true
  core-js: false
  # version selectors are supported
  nx@21.6.4 || 21.6.5: true
  • Packages not listed are unreviewed and blocked by default.
  • strictDepBuilds: true (default) ⇒ unreviewed builds make install exit non-zero (ERR_PNPM_IGNORED_BUILDS). Set false to warn instead.
  • During install, unreviewed packages with build scripts are auto-added to pnpm-workspace.yaml with a placeholder so you can set true/false.

allowBuilds replaces the removed onlyBuiltDependencies, neverBuiltDependencies, ignoredBuiltDependencies, onlyBuiltDependenciesFile, and ignoreDepScripts.

Approving builds

pnpm approve-builds            # interactive prompt
pnpm approve-builds --all      # approve all pending
pnpm approve-builds esbuild fsevents !core-js   # ! = deny
pnpm add --allow-build=esbuild my-bundler       # approve while adding
pnpm add -g --allow-build=esbuild esbuild       # global (replaces approve-builds -g)

Escape hatch (dangerous)

dangerouslyAllowAllBuilds: true   # runs ALL build scripts now and in the future — avoid

Minimum release age

Delay installing freshly published versions so malicious releases (usually pulled within an hour) are avoided. Applies to all deps, including transitive.

minimumReleaseAge: 1440          # minutes; default 1440 (1 day) since v11
minimumReleaseAgeExclude:        # always install newest of these immediately
  - webpack
  - '@myorg/*'
  - nx@21.6.5                    # exempt a specific version
  • minimumReleaseAgeStrict — when no in-range version satisfies the age, fail (default when you set minimumReleaseAge yourself) vs. fall back.
  • minimumReleaseAgeIgnoreMissingTime — skip the check for registries that omit the time field (default true).

Trust policy

Fail if a package's trust level decreased vs earlier releases (e.g. was published by a trusted publisher, now only has provenance or nothing).

trustPolicy: no-downgrade        # off (default) | no-downgrade
trustPolicyExclude:
  - 'chokidar@4.0.3'
trustPolicyIgnoreAfter: 525600   # ignore the check for pkgs published > N minutes ago

Block exotic transitive sources

blockExoticSubdeps: true   # default

When true, only direct dependencies may use exotic sources (git repos, direct tarball URLs); all transitive deps must come from a trusted source (registry, local path, workspace link, or trusted GitHub repos).

Lockfile integrity

Since v11, a downloaded tarball whose hash doesn't match pnpm-lock.yaml is a hard error (ERR_PNPM_TARBALL_INTEGRITY) — protecting committed lockfiles from a compromised registry/proxy. --force and pnpm update do not bypass it.

pnpm install --update-checksums   # narrow opt-in after verifying the new bytes

Pin packages to their registry

If you install from more than one registry, use namedRegistries aliases for packages that must come from a specific one. Since v11.20.0 pnpm records these under registry-qualified lockfile keys (<name>@<registryName>:<version>), so a package can't be silently substituted by another registry publishing the same name/version.

Lockfile scanners: two-document lockfile

pnpm-lock.yaml may be a two-document file. A vulnerability scanner or SBOM generator that reads only the first document reports "no dependencies" (and no vulnerabilities) without failing — verify your tooling handles both documents.

Trusted store/cache

The content-addressable store, global virtual store, and metadata cache are part of pnpm's trust domain. Share them only between mutually trusting users/jobs and protect with filesystem permissions. verifyStoreIntegrity (default true) detects accidental corruption but does not make a writable-by-untrusted store safe.

Key Points

  • Dependency build scripts are blocked until approved via allowBuilds / pnpm approve-builds; unreviewed builds fail by default (strictDepBuilds).
  • minimumReleaseAge (default 1 day in v11) delays new releases; trustPolicy: no-downgrade blocks trust regressions; blockExoticSubdeps limits transitive git/tarball sources.
  • Tarball integrity mismatches are fatal; use --update-checksums only after verification.
  • Treat the store/cache as trusted shared state.
<!-- Source references: - https://pnpm.io/settings/build#allowbuilds - https://pnpm.io/cli/approve-builds - https://pnpm.io/settings/dependency-resolution#minimumreleaseage - https://pnpm.io/settings/dependency-resolution#trustpolicy - https://pnpm.io/settings/dependency-resolution#blockexoticsubdeps - https://pnpm.io/supply-chain-security -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.