pnpm skillA
pnpm is agent-read markdown (skill) from antfu/skills: Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified before it reaches your agent: the main file against the SHA-256 recorded here, the others against the git hashes of its source commit. The deterministic audit below grades the latest version, and the same checks always give the same file the same grade.
What the file says
pnpm is a fast, disk space efficient package manager. It uses a content-addressable store to deduplicate packages across all projects on a machine, and enforces strict dependency resolution by default, preventing phantom dependencies. **pnpm v12 is a Rust rewrite** of v11: stable, and keeps v11's commands, flags, settings, and lockfile format — so most guidance here applies to both. A handful of v12 behaviors differ (git deps resolve via HTTPS, project-aware global bins, other package managers, `packageImportMethod: auto` hardlinks first on Linux, `--resolution-only` removed) — see best-practices-migration. **Configuration model (important):** pnpm settings live in `pnpm-workspace.yaml` (and the global `config.yaml`) using **camelCase** keys. `.npmrc` is used **only** for authentication/registry credentials, and the `pnpm` field of `package.json` is no longer read. When working in a pnpm project, check `pnpm-workspace.yaml` for settings/workspace structure and `.npmrc` only for auth. Always use `--frozen-lockfile` (or `pnpm ci`) in CI. …
Read the whole file at its exact version.
How to install
mdr add antfu/skills/pnpm@v2026.9.25mdr add antfu/skills/pnpm@sha256:a4bcad9e69af08b4Pin to a label to follow the author's releases, or to a sha256 for exact bytes. Either way the resolved hash is written to mdr.lock, and mdr install fetches those bytes again and checks them, so it installs them exactly or fails.
[](https://markdownregistry.com/a/art_ilnc7hpuwurqjemw)
0 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| v2026.9.25 latest | 2026-09-28 | d02c484 | 5,122 B | A | view · diff |
| v2026.6.22 | 2026-06-23 | 2814e65 | 4,082 B | A | view · diff |
| v2026.1.28 | 2026-01-28 | 5cae97c | 2,957 B | A | view · diff |
| v2026.1.28 | 2026-01-28 | 70cc91a | 2,819 B | A | view · diff |
| v2026.1.28 | 2026-01-28 | b4775da | 2,820 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (5122 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
antfu/skills · 5,927 stars · license MIT · pushed 2026-09-28 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ilnc7hpuwurqjemw GET https://markdownregistry.com/api/v1/resolve?ref=antfu/skills/pnpm GET https://markdownregistry.com/api/v1/blob/a4bcad9e69af08b4bc7296ab168627ecd19c070f94007858d05daff0d8dce099
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.