PluginBench
Skill
Pass
Audit score 90

pnpm

antfu/skills

Fast, disk-space efficient Node.js package manager with strict dependency resolution and monorepo support.

What is pnpm?

pnpm is a package manager for Node.js projects that uses content-addressable storage to deduplicate packages and enforces strict dependency resolution by default. Use it when you need efficient dependency management, monorepo/workspace support, or advanced features like catalogs, patches, and overrides.

  • Manage dependencies with strict resolution that prevents phantom dependencies
  • Configure and run monorepo workspaces with shared lockfiles and task orchestration
  • Define centralized dependency versions via catalogs and enforce overrides across projects
  • Patch third-party packages and share configuration across repositories via config dependencies
  • Support multi-ecosystem dependencies (npm, Python, Cargo) in a single project
  • Implement supply-chain security controls including build approval and minimum release age checks

How to install pnpm

npx skills add https://github.com/antfu/skills --skill pnpm
Prerequisites
  • Node.js installed on your system
Claude Code
Cursor
Windsurf
Cline

How to use pnpm

  1. 1.Run `pnpm install` to install dependencies from pnpm-lock.yaml or create a new lockfile
  2. 2.Configure workspace structure in `pnpm-workspace.yaml` using camelCase keys for settings
  3. 3.Use `pnpm add <package>` to add dependencies or `pnpm remove <package>` to remove them
  4. 4.Run scripts with `pnpm run <script>` or use `pnpm dlx` to execute packages without installing
  5. 5.In CI environments, use `pnpm ci` or `pnpm install --frozen-lockfile` to ensure reproducible installs
  6. 6.Define catalogs in `pnpm-workspace.yaml` to centralize dependency versions across the workspace

Use cases

Good for
  • Setting up a monorepo with multiple interdependent packages and shared configuration
  • Reducing disk space by deduplicating identical package versions across projects on a machine
  • Enforcing consistent dependency versions across a workspace using catalogs and overrides
  • Patching vulnerabilities or bugs in third-party packages without waiting for upstream fixes
  • Orchestrating cross-project build and test tasks with dependency graphs and concurrency controls
Who it's for
  • Node.js developers managing single or multi-project repositories
  • DevOps engineers setting up CI/CD pipelines with pnpm workspaces
  • Monorepo maintainers needing workspace task orchestration and dependency management
  • Teams requiring supply-chain security controls and build approval workflows

pnpm FAQ

What is the difference between pnpm and npm?

pnpm uses a content-addressable store to deduplicate packages across projects, saving disk space, and enforces strict dependency resolution by default to prevent phantom dependencies. It also has native monorepo support with workspace task orchestration.

Where should I put pnpm configuration?

Use `pnpm-workspace.yaml` for pnpm settings (camelCase keys), `.npmrc` only for authentication and registry credentials, and avoid using the `pnpm` field in `package.json`. Global settings go in `config.yaml`.

How do I set up a monorepo with pnpm?

Create a `pnpm-workspace.yaml` file at the root listing your workspace packages (e.g., `packages: ['packages/*']`), then use `pnpm install` to install all dependencies. Use `pnpm -r` to run commands across all packages.

What is the global virtual store?

The global virtual store allows multiple projects to share a single `node_modules` directory, reducing disk usage and enabling multi-agent setups with git worktrees. It isolates global packages and provides project-aware binary shims.

How do I ensure reproducible installs in CI?

Use `pnpm ci` or `pnpm install --frozen-lockfile` in CI environments to install exact versions from the lockfile without updating it.

Full instructions (SKILL.md)

Source of truth, from antfu/skills.


name: pnpm description: Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store. metadata: author: Anthony Fu version: "2026.9.25" source: Generated from https://github.com/pnpm/pnpm, scripts located at https://github.com/antfu/skills

pnpm is a fast, disk space efficient package manager. It uses a content-addressable store to deduplicate packages across all projects on a machine, and enforces strict dependency resolution by default, preventing phantom dependencies.

pnpm v12 is a Rust rewrite of v11: stable, and keeps v11's commands, flags, settings, and lockfile format — so most guidance here applies to both. A handful of v12 behaviors differ (git deps resolve via HTTPS, project-aware global bins, other package managers, packageImportMethod: auto hardlinks first on Linux, --resolution-only removed) — see best-practices-migration.

Configuration model (important): pnpm settings live in pnpm-workspace.yaml (and the global config.yaml) using camelCase keys. .npmrc is used only for authentication/registry credentials, and the pnpm field of package.json is no longer read. When working in a pnpm project, check pnpm-workspace.yaml for settings/workspace structure and .npmrc only for auth. Always use --frozen-lockfile (or pnpm ci) in CI.

The skill is based on pnpm 12.x, generated at 2026-09-25. It covers v11+v12 behavior (config split, isolated global packages, allowBuilds, pmOnFail, global virtual store, native release management, workspace task orchestration, and experimental Python/Cargo support) where current docs describe them.

Core

TopicDescriptionReference
CLI Commandsinstall/add/remove/update, run, dlx/pnx, workspace, runtime, publishing (version, view, sbom, stage)core-cli
Configurationpnpm-workspace.yaml settings (camelCase), global config.yaml, packageConfigs, .npmrc authcore-config
WorkspacesMonorepo support: filtering, workspace protocol, shared lockfile, packageConfigscore-workspaces
StoreContent-addressable store, virtual store, node linker modes, frozen/read-only storecore-store

Features

TopicDescriptionReference
CatalogsCentralized dependency versions; catalogMode, catalog: in overridesfeatures-catalogs
OverridesForce versions (incl. transitive & peer deps); packageExtensionsfeatures-overrides
PatchesModify third-party packages; patchedDependencies in pnpm-workspace.yamlfeatures-patches
AliasesInstall under custom names (npm:) and registry aliases (namedRegistries)features-aliases
Hooks.pnpmfile.mjs hooks (readPackage, updateConfig, beforePacking), finders, resolvers/fetchersfeatures-hooks
Peer DependenciesAuto-install, strict mode, rules, dedupePeers, peers checkfeatures-peer-deps
Config DependenciesShare hooks/settings/catalogs/patches across repos via configDependenciesfeatures-config-dependencies
Global Virtual Store & ShimsShared node_modules, git-worktree multi-agent setups, isolated global packages, project-aware bins, other package managersfeatures-global-virtual-store
Supply-Chain SecurityBuild approval (allowBuilds), minimumReleaseAge, trustPolicy, lockfile integrityfeatures-supply-chain-security
Task OrchestrationCross-project task graphs (tasks/dependsOn), concurrency groups, priority, pnpm pipelinefeatures-task-orchestration
Release ManagementNative versioning: pnpm change/version -r/lane, lanes, epics, fixed groupsfeatures-versioning
Multi-EcosystemPython (pypi:) and Cargo (crate:) dependencies alongside npm (experimental)features-multi-ecosystem

Best Practices

TopicDescriptionReference
CI/CD SetupGitHub Actions, GitLab, Docker, pnpm ci, store caching, frozen lockfilesbest-practices-ci
Migrationnpm/Yarn → pnpm, phantom deps, and pnpm v10 → v11 → v12 upgrade notesbest-practices-migration
PerformanceInstall optimizations, allowBuilds, global virtual store, workspace parallelizationbest-practices-performance