All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-task-orchestration.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workspace Task Orchestration

pnpm -r run <script> schedules a graph of workspace tasks. A task is <project>#<script>; it becomes ready once every task it depends on succeeds, and ready tasks run under --workspace-concurrency. Independent tasks run in unpredictable order.

Declaring task dependencies

Configure under tasks in pnpm-workspace.yaml:

tasks:
  build:
    dependsOn:
      - ^build        # build in each workspace dependency
  test:
    dependsOn:
      - build         # build in the same project
  • build → the build task in the same project.
  • ^build → the build task in each selected workspace dependency.
  • A task with no tasks entry defaults to depending on the same task in its workspace deps (an unconfigured build behaves as dependsOn: ['^build']), preserving deps-before-dependents order.
  • Once a task has an entry, an omitted dependsOn means dependsOn: []. If you set another field (e.g. concurrency) and still want topological order, declare dependsOn: ['^build'] explicitly.
  • Task deps stay within the --filter/includeWorkspaceRoot selection. A project missing the named script is a pass-through (reported skipped, doesn't break the chain).

Per-task concurrency

tasks:
  build:
    concurrency: 2          # max 2 instances of build across projects
    dependsOn: ['^build']

Separate from --workspace-concurrency; a task waiting for its slot doesn't occupy a workspace slot.

Concurrency groups (v12.5.0)

Machine-wide limits shared across pnpm processes that use the same stateDir (including pnpm pipeline):

tasks:
  test:rust:
    concurrencyGroup: cargo
    dependsOn: []
concurrencyGroups:
  cargo: 2                  # at most 2 cargo tasks at once, across processes
  • A nested pnpm run in the same group reuses its parent's slot. Slots release on process exit/crash.
  • A missing/zero group limit doesn't restrict. Changing stateDir creates a separate slot pool.

Task priority (v12.6.0)

priority (integer, default 0) orders waiting tasks for available slots — higher runs first, ties broken by arrival:

tasks:
  build:critical: { concurrencyGroup: build, priority: 10 }
  build:cleanup:  { concurrencyGroup: build, priority: -1 }

Inspecting groups (v12.6.0)

pnpm tasks status [groups...]   # running + waiting tasks per group
pnpm pm tasks status            # force built-in if a "tasks" script shadows it

Inspecting the graph

pnpm -r run --dry-run build         # stable topological ordering, no scripts run
pnpm -r run --dry-run --json test   # nodes + edges as JSON

Recursive run options

  • --resume-from <pkg> — resume at a package's task, skipping tasks a prior run of the same invocation recorded as passed.
  • --reverse — reverse every edge (dependents run first).
  • --no-bail — keep running independent ready tasks after a failure (default --bail cancels running tasks and stops dispatching).
  • Output is inherited when only one script can run at a time; otherwise piped. Use --stream for immediate prefixed output or --aggregate-output.

Cycles

A cycle fails before any script with ERR_PNPM_TASK_CYCLE. Set ignoreWorkspaceCycles: true only for deliberate cycles (pnpm warns and drops ordering among members).

Commands that ignore tasks

--no-sort and --parallel (implies --no-sort) ignore tasks declarations. Recursive exec has no script name so it doesn't join dependsOn, but still uses dependency-aware scheduling and --resume-from.

pnpm pipeline (v12.4.0, experimental)

Runs a named set of tasks the way a CI job would: frozen install, then the affected projects' task graph, with cached results restored.

tasks:
  build: { dependsOn: ['^build'], outputs: ['dist/**'], inputs: ['src/**'], env: ['NODE_ENV'] }
  test:  { dependsOn: ['build'], outputs: [] }
  lint:  { outputs: [] }
pipelines:
  default: [build, test, lint]
  release: [build]
pnpm pipeline           # runs the "default" pipeline
pnpm pipeline release
pnpm pipeline --dry-run --json
pnpm pipeline --full    # every project, not just affected-since-base
pnpm pipeline --base <ref>   # affected diff base (default origin/main, or pipelineBase)
pnpm pipeline --no-cache
  • Caching: a task is cacheable only when it declares outputs (outputs: [] = "produces no files", makes a linter/test cacheable). inputs narrows the cache key (+glob adds to the default); env names hashed vars; cache: false opts out. The key also covers script text, dependency task keys, the lockfile, and the runtime. A hit restores files and replays logs.
  • A plain recursive pnpm run never restores from the pipeline cache; outputs/inputs/env/cache/cargoTargetDir are read by pnpm pipeline only.
  • Cargo build state: cargoTargetDir: target keeps a task's Cargo target dir between runs/worktrees via immutable snapshots.

Other dependency-aware commands

Workspace install, rebuild, pack, publish, stage, and lifecycle work start a project's work as soon as its workspace deps finish — following the package graph (not tasks), no longer waiting for unrelated topological groups.

<!-- Source references: - https://pnpm.io/workspace-task-orchestration - https://pnpm.io/cli/tasks - https://pnpm.io/cli/pipeline -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.