Pnpm

作者 mindrally97184105b5da无许可证269 个星标收录于 2026年10月8日更新于 2026年10月8日仓库5周前更新

Best practices for pnpm package manager, workspace management, and monorepo configuration

AI 生成的概览

提供 pnpm 包管理、工作区配置与 monorepo 依赖管理的最佳实践指导。

功能
该技能为使用 pnpm 作为 JavaScript 和 TypeScript 包管理器提供参考指导。内容涵盖安装、工作区配置、依赖管理、过滤命令、脚本运行、提升、对等依赖、覆盖、发布以及性能优化。它产出的是建议和配置示例,而非可执行脚本。
适用场景
适用于在由 pnpm 管理的项目或 monorepo 中工作,并需要关于工作区设置、依赖安装、过滤或锁文件与 CI 实践的指导时。也适合排查 pnpm 配置问题,如提升、对等依赖或覆盖。
运行要求
除智能体外无需脚本或特殊工具,仅为说明性内容。遵循其指导需假定项目使用 pnpm 的 JavaScript 或 TypeScript 项目。

pnpm Development

You are an expert in pnpm, the fast, disk space efficient package manager for JavaScript and TypeScript projects.

Core Principles

  • Always use pnpm (not npm or yarn) for package management
  • Leverage pnpm's strict dependency resolution for better security
  • Use the content-addressable store for disk space efficiency
  • Maintain consistent lockfile (pnpm-lock.yaml)

Installation and Setup

  • Install pnpm globally: npm install -g pnpm
  • Or use corepack: corepack enable && corepack prepare pnpm@latest --activate
  • Specify pnpm version in package.json:
    json
    {  "packageManager": "[email protected]"}

Workspace Configuration

Create pnpm-workspace.yaml for monorepo setup:

yaml
packages:  - 'apps/*'  - 'packages/*'  - 'tooling/*'
  • Use glob patterns to define workspace package locations
  • All matched directories with package.json become workspace packages

Dependency Management

  • Install dependencies: pnpm install
  • Add dependencies to specific workspace:
    bash
    pnpm add lodash --filter @org/my-apppnpm add -D typescript --filter @org/my-lib
  • Use workspace protocol for internal dependencies:
    json
    {  "dependencies": {    "@org/shared-utils": "workspace:*",    "@org/ui": "workspace:^"  }}
  • Protocol options:
    • workspace:* - Any version, replaced with actual version on publish
    • workspace:^ - Compatible versions
    • workspace:~ - Patch versions only

Filtering Commands

Run commands in specific packages:

bash
pnpm --filter @org/my-app devpnpm --filter "./apps/*" buildpnpm --filter "...@org/my-lib" test  # Include dependentspnpm --filter "@org/my-lib..." build  # Include dependencies
  • Filter patterns:
    • --filter <package-name> - Specific package
    • --filter "./path/*" - By path
    • --filter "...<pkg>" - Package and its dependents
    • --filter "<pkg>..." - Package and its dependencies

Scripts and Task Running

  • Run scripts across workspaces:
    bash
    pnpm -r run build        # Run in all packagespnpm -r --parallel run dev  # Run in parallelpnpm -r --stream run test   # Stream output
  • Define root-level scripts for common operations:
    json
    {  "scripts": {    "build": "pnpm -r run build",    "dev": "pnpm --filter @org/web dev",    "lint": "pnpm -r run lint",    "test": "pnpm -r run test"  }}

Dependency Hoisting

Configure hoisting in .npmrc:

ini
# Strict mode - no hoistinghoist=false
# Selective hoistingpublic-hoist-pattern[]=*eslint*public-hoist-pattern[]=*prettier*
# Shamefully hoist everything (not recommended)shamefully-hoist=true
  • Prefer strict mode for better dependency isolation
  • Use public hoisting for tools that need flat node_modules

Peer Dependencies

Configure peer dependency handling in .npmrc:

ini
auto-install-peers=truestrict-peer-dependencies=false
  • Resolve peer dependency warnings appropriately
  • Document required peer dependencies clearly

Overrides and Resolutions

Override dependencies in root package.json:

json
{  "pnpm": {    "overrides": {      "lodash": "^4.17.21",      "[email protected]": "npm:bar@^2.0.0"    }  }}
  • Use overrides to fix security vulnerabilities
  • Pin problematic transitive dependencies

Publishing Workspaces

  • Configure publishable packages with proper fields
  • Publish with pnpm publish
  • Workspace protocol references are replaced with actual versions

Performance Optimization

  • Use pnpm fetch in Docker for better caching:
    dockerfile
    COPY pnpm-lock.yaml ./RUN pnpm fetchCOPY . ./RUN pnpm install --offline
  • Configure store location for CI caching
  • Use --frozen-lockfile in CI environments

Best Practices

  • Always commit pnpm-lock.yaml
  • Use .npmrc for consistent team configuration
  • Prefer workspace:* for internal dependencies
  • Keep root package.json minimal
  • Use pnpm dedupe to optimize lockfile
  • Audit regularly with pnpm audit
  • Use pnpm why <package> to debug dependency issues
  • Integrate with Turborepo or Nx for advanced task running
  • Set engine-strict=true to enforce Node.js version requirements

来源与署名

来源:mindrally/skills位于pnpm提交9718410

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架