pnpm
Best practices for pnpm package manager, workspace management, and monorepo configuration
What this skill does
# pnpm Development
You are an expert in pnpm, the fast, disk space efficient package manager for JavaScript and TypeScript projects.
## Core Principles
- Always use pnpm (not npm or yarn) for package management
- Leverage pnpm's strict dependency resolution for better security
- Use the content-addressable store for disk space efficiency
- Maintain consistent lockfile (`pnpm-lock.yaml`)
## Installation and Setup
- Install pnpm globally: `npm install -g pnpm`
- Or use corepack: `corepack enable && corepack prepare pnpm@latest --activate`
- Specify pnpm version in `package.json`:
```json
{
"packageManager": "[email protected]"
}
```
## Workspace Configuration
Create `pnpm-workspace.yaml` for monorepo setup:
```yaml
packages:
- 'apps/*'
- 'packages/*'
- 'tooling/*'
```
- Use glob patterns to define workspace package locations
- All matched directories with `package.json` become workspace packages
## Dependency Management
- Install dependencies: `pnpm install`
- Add dependencies to specific workspace:
```bash
pnpm add lodash --filter @org/my-app
pnpm add -D typescript --filter @org/my-lib
```
- Use workspace protocol for internal dependencies:
```json
{
"dependencies": {
"@org/shared-utils": "workspace:*",
"@org/ui": "workspace:^"
}
}
```
- Protocol options:
- `workspace:*` - Any version, replaced with actual version on publish
- `workspace:^` - Compatible versions
- `workspace:~` - Patch versions only
## Filtering Commands
Run commands in specific packages:
```bash
pnpm --filter @org/my-app dev
pnpm --filter "./apps/*" build
pnpm --filter "...@org/my-lib" test # Include dependents
pnpm --filter "@org/my-lib..." build # Include dependencies
```
- Filter patterns:
- `--filter <package-name>` - Specific package
- `--filter "./path/*"` - By path
- `--filter "...<pkg>"` - Package and its dependents
- `--filter "<pkg>..."` - Package and its dependencies
## Scripts and Task Running
- Run scripts across workspaces:
```bash
pnpm -r run build # Run in all packages
pnpm -r --parallel run dev # Run in parallel
pnpm -r --stream run test # Stream output
```
- Define root-level scripts for common operations:
```json
{
"scripts": {
"build": "pnpm -r run build",
"dev": "pnpm --filter @org/web dev",
"lint": "pnpm -r run lint",
"test": "pnpm -r run test"
}
}
```
## Dependency Hoisting
Configure hoisting in `.npmrc`:
```ini
# Strict mode - no hoisting
hoist=false
# Selective hoisting
public-hoist-pattern[]=*eslint*
public-hoist-pattern[]=*prettier*
# Shamefully hoist everything (not recommended)
shamefully-hoist=true
```
- Prefer strict mode for better dependency isolation
- Use public hoisting for tools that need flat node_modules
## Peer Dependencies
Configure peer dependency handling in `.npmrc`:
```ini
auto-install-peers=true
strict-peer-dependencies=false
```
- Resolve peer dependency warnings appropriately
- Document required peer dependencies clearly
## Overrides and Resolutions
Override dependencies in root `package.json`:
```json
{
"pnpm": {
"overrides": {
"lodash": "^4.17.21",
"[email protected]": "npm:bar@^2.0.0"
}
}
}
```
- Use overrides to fix security vulnerabilities
- Pin problematic transitive dependencies
## Publishing Workspaces
- Configure publishable packages with proper fields
- Publish with `pnpm publish`
- Workspace protocol references are replaced with actual versions
## Performance Optimization
- Use `pnpm fetch` in Docker for better caching:
```dockerfile
COPY pnpm-lock.yaml ./
RUN pnpm fetch
COPY . ./
RUN pnpm install --offline
```
- Configure store location for CI caching
- Use `--frozen-lockfile` in CI environments
## Best Practices
- Always commit `pnpm-lock.yaml`
- Use `.npmrc` for consistent team configuration
- Prefer `workspace:*` for internal dependencies
- Keep root `package.json` minimal
- Use `pnpm dedupe` to optimize lockfile
- Audit regularly with `pnpm audit`
- Use `pnpm why <package>` to debug dependency issues
- Integrate with Turborepo or Nx for advanced task running
- Set `engine-strict=true` to enforce Node.js version requirements
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.