pnpm

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.

Category
Engineering
Skill
112 of 261
Source
Kevin wiki

pnpm is a fast, disk space efficient package manager. It uses a content-addressable store to deduplicate packages across all projects on a machine, and enforces strict dependency resolution by default, preventing phantom dependencies.

Configuration model (important): pnpm settings now live in pnpm-workspace.yaml (and the global config.yaml) using camelCase keys. .npmrc is used only for authentication/registry credentials, and the pnpm field of package.json is no longer read. When working in a pnpm project, check pnpm-workspace.yaml for settings/workspace structure and .npmrc only for auth. Always use --frozen-lockfile (or pnpm ci) in CI.

The skill is based on pnpm 10.x, generated at 2026-06-22. It also covers v11 behavior changes (config split, isolated global packages, allowBuilds, pmOnFail, global virtual store) where current docs describe them.

Core

TopicDescriptionReference
CLI Commandsinstall/add/remove/update, run, dlx/pnx, workspace, runtime, publishing (version, view, sbom, stage)core-cli (references/core-cli.md)
Configurationpnpm-workspace.yaml settings (camelCase), global config.yaml, packageConfigs, .npmrc authcore-config (references/core-config.md)
WorkspacesMonorepo support: filtering, workspace protocol, shared lockfile, packageConfigscore-workspaces (references/core-workspaces.md)
StoreContent-addressable store, virtual store, node linker modes, frozen/read-only storecore-store (references/core-store.md)

Features

TopicDescriptionReference
CatalogsCentralized dependency versions; catalogMode, catalog: in overridesfeatures-catalogs (references/features-catalogs.md)
OverridesForce versions (incl. transitive & peer deps); packageExtensionsfeatures-overrides (references/features-overrides.md)
PatchesModify third-party packages; patchedDependencies in pnpm-workspace.yamlfeatures-patches (references/features-patches.md)
AliasesInstall under custom names (npm:) and registry aliases (namedRegistries)features-aliases (references/features-aliases.md)
Hooks.pnpmfile.mjs hooks (readPackage, updateConfig, beforePacking), finders, resolvers/fetchersfeatures-hooks (references/features-hooks.md)
Peer DependenciesAuto-install, strict mode, rules, dedupePeers, peers checkfeatures-peer-deps (references/features-peer-deps.md)
Config DependenciesShare hooks/settings/catalogs/patches across repos via configDependenciesfeatures-config-dependencies (references/features-config-dependencies.md)
Global Virtual StoreShared node_modules, git-worktree multi-agent setups, isolated global packagesfeatures-global-virtual-store (references/features-global-virtual-store.md)
Supply-Chain SecurityBuild approval (allowBuilds), minimumReleaseAge, trustPolicy, lockfile integrityfeatures-supply-chain-security (references/features-supply-chain-security.md)

Best Practices

TopicDescriptionReference
CI/CD SetupGitHub Actions, GitLab, Docker, pnpm ci, store caching, frozen lockfilesbest-practices-ci (references/best-practices-ci.md)
Migrationnpm/Yarn → pnpm, phantom deps, and pnpm v10 → v11 config migrationbest-practices-migration (references/best-practices-migration.md)
PerformanceInstall optimizations, allowBuilds, global virtual store, workspace parallelizationbest-practices-performance (references/best-practices-performance.md)