All skills
antfu avatar

/pnpm

@d02c484 official
by Anthony Fuantfu/skills5.9k stars
335

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Use this Skill: https://skilld.dev/gh/antfu/skills/pnpm

This session only. Nothing lands on disk.

referencesfeatures-versioning.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Release Management (v11.13.0+)

pnpm versions and releases a workspace without a separate release tool. Two halves:

  1. As you work, pnpm change records change intents — markdown files in .changeset/ (changesets format) naming affected packages, bump types, and a changelog summary. Commit them with the change.
  2. At release, bare pnpm version -r consumes pending intents: bumps versions, propagates to dependents, writes changelogs, and records what it consumed in a committed ledger.

An existing .changeset/ keeps working; you can still use the Changesets CLI instead.

Recording a change

pnpm change                                              # interactive prompt
pnpm change --bump patch --summary "Fix crash" @ex/core  # non-interactive (scripts)
pnpm change status                                       # pending intents + release plan

Writes e.g. .changeset/calm-cats-resolve.md:

---
"@example/core": minor
---
Added a `--watch` flag to the build command.

--bump accepts none|patch|minor|major (none = explicit "no release"). When two projects share a name, reference one by ./-prefixed directory ("./packages/cli": minor).

Releasing

pnpm version -r              # consume intents, bump, changelog, ledger
pnpm version -r --dry-run    # preview
pnpm version -r --filter …   # narrow (selection expands to settle deps/fixed groups)

No git commit/tag is created (many packages, many versions) — commit yourself, then pnpm publish -r. Working tree must be clean unless --dry-run/--no-git-checks. Every package bumped through a workspace: range to a bumped dependency is bumped too. First release of a package publishes the manifest version verbatim (v11.16.0+).

Configuration (versioning in pnpm-workspace.yaml)

versioning:
  fixed:
    - ['@example/cli', '@example/napi']   # always release at one shared version
  ignore:
    - '@example/internal'                 # excluded from versioning + propagation
  maxBump: minor                          # cap the bump this checkout may apply
  lanes:
    '@example/cli': alpha                 # parallel release track
  epics:
    - lead: '@example/app'
      packages: ['./packages/**', '!./packages/private-*']
  changelog:
    storage: repository                   # commit CHANGELOG.md (default: registry)
  • fixed groups release together at the highest current version bumped by the largest needed bump; must move lanes together and sit wholly in/out of an epic.
  • changelog.storage: registry (default) composes each section at publish time into the tarball, no committed CHANGELOG.md; repository commits one per package.

Lanes

A lane is a parallel release track. A package on lane alpha releases X.Y.Z-alpha.N prereleases from the same runs that ship stable versions of everything on main.

pnpm lane alpha --filter @example/cli   # move onto alpha (--filter required)
pnpm lane main --filter @example/cli    # graduate to stable on next version -r
pnpm lane                               # show membership

N counts from 0 and restarts when the stable target changes. Lane names: alphanumerics/hyphens, not purely numeric; main is reserved.

Epics

An epic ties member packages to a lead, constraining each member's major to a band: while the lead is on major M, members live in M*100…M*100+99 (lead on 11.x ⇒ members in 1100–1199). A bump past the ceiling is rejected until the lead advances; when the lead hits a new major, members re-base to the band floor in the same plan.

Validation & the ledger

pnpm change check   # (v12.4.0) validate committed versions against epic bands + fixed groups; reads no intents — run on every PR

pnpm version -r records consumed intents in .changeset/ledger.yaml (committed, append-only). Consumption is tracked per project — an intent file is deleted only once every project it names has released, making cherry-picks/merge-backs between release branches safe.

<!-- Source references: - https://pnpm.io/versioning - https://pnpm.io/cli/change - https://pnpm.io/cli/lane - https://pnpm.io/cli/version - https://pnpm.io/settings/versioning -->

Source: SKILL.md on GitHub

No alerts3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is a comprehensive documentation reference for the pnpm package manager. It provides detailed guides on CLI commands, monorepo management, and supply-chain security features. No malicious patterns or security risks were identified.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    2/15 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d02c484. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 days ago
Other metadata
metadata
{
  "author": "Anthony Fu",
  "version": "2026.9.25",
  "source": "Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills"
}
  • pnpm
  • node-js
  • package-manager
  • workspaces
  • monorepo
  • dependencies
  • lockfile
  • catalogs
  • patches
  • overrides

README badge

README badge for antfu/skills/pnpm

Instructs Claude on pnpm commands, workspace configuration, and dependency management features like catalogs, patches, and overrides. Use this when working with pnpm monorepos, configuring strict dependency resolution, or managing workspace-level dependency versions and package patches.

Generated from the current SKILL.md.

Does this skill work with npm or Yarn projects?
This skill is specifically for pnpm. The SKILL.md includes migration guidance for moving from npm or Yarn to pnpm, but does not provide instructions for managing npm or Yarn projects directly.
What version of pnpm does this skill cover?
The skill is based on pnpm 10.x, generated on 2026-01-28.
Can I use this skill to manage monorepos?
Yes. The skill covers pnpm workspaces with filtering, the workspace protocol, shared lockfiles, and centralized dependency management through catalogs.
What should I check before running pnpm commands in a project?
Check for pnpm-workspace.yaml and .npmrc files to understand the workspace structure and configuration. In CI environments, always use --frozen-lockfile.
Does this skill cover patching and overriding dependencies?
Yes. The skill includes support for patches to modify third-party packages and overrides to force specific versions of dependencies, including transitive ones.

Generated from the current SKILL.md. These answers refresh after source changes.