6.7 KiB
name, description
| name | description |
|---|---|
| migration-to-pnpm | Migrating from npm or Yarn to pnpm with minimal friction |
Migration to pnpm
Guide for migrating existing projects from npm or Yarn to pnpm, plus upgrading pnpm v10 → v11.
Upgrading pnpm v10 → v11
v11 changes how configuration is read. Most of it is mechanical — run the codemod:
cd /path/to/project
pnpx codemod run pnpm-v10-to-v11
The codemod automatically:
- Moves
package.json#pnpmsettings intopnpm-workspace.yaml(thepnpmfield is no longer read). - Splits
.npmrc: only auth/registry settings stay in.npmrc; every other key moves topnpm-workspace.yamlas camelCase (e.g.node-linker→nodeLinker). Per-subproject.npmrcfiles becomepackageConfigs["<name>"]. - Consolidates build settings (
onlyBuiltDependencies,neverBuiltDependencies,ignoredBuiltDependencies,onlyBuiltDependenciesFile) into oneallowBuilds: { name: true|false }map. - Replaces
managePackageManagerVersions/packageManagerStrict/packageManagerStrictVersionwithpmOnFail: download|ignore|warn|error. - Renames
allowNonAppliedPatches→allowUnusedPatches,auditConfig.ignoreCves→auditConfig.ignoreGhsas. - Converts
useNodeVersion→devEngines.runtime, and bumpspackageManager.
Manual follow-ups (not automatable):
- Convert
CVE-…IDs toGHSA-…inauditConfig.ignoreGhsas. ignorePatchFailuresremoved — failed patches now always throw.npm_config_*env vars →pnpm_config_*(CI, shell profiles, Docker).pnpm link <name>→ use a path (pnpm link ./foo);pnpm link --global→pnpm add -g ..pnpm install -g(no args) andpnpm serverremoved.- A
package.jsonscript namedclean/setup/deploy/rebuildnow shadows the built-in — usepnpm pm <name>for the built-in.
Migrating from npm / Yarn
Quick Migration
From npm
# Remove npm lockfile and node_modules
rm -rf node_modules package-lock.json
# Install with pnpm
pnpm install
From Yarn
# Remove yarn lockfile and node_modules
rm -rf node_modules yarn.lock
# Install with pnpm
pnpm install
Import Existing Lockfile
pnpm can import existing lockfiles:
# Import from npm or yarn lockfile
pnpm import
# This creates pnpm-lock.yaml from:
# - package-lock.json (npm)
# - yarn.lock (yarn)
# - npm-shrinkwrap.json (npm)
Handling Common Issues
Phantom Dependencies
pnpm is strict about dependencies. If code imports a package not in package.json, it will fail.
Problem:
// Works with npm (hoisted), fails with pnpm
import lodash from 'lodash' // Not in dependencies, installed by another package
Solution: Add missing dependencies explicitly:
pnpm add lodash
Missing Peer Dependencies
pnpm reports peer dependency issues by default.
Option 1: Let pnpm auto-install (default in v8+):
autoInstallPeers: true
Option 2: Install manually:
pnpm add react react-dom
Option 3: Suppress warnings if acceptable:
peerDependencyRules:
ignoreMissing:
- react
Symlink Issues
Some tools don't work with symlinks. Use hoisted mode:
nodeLinker: hoisted
Or hoist specific packages:
publicHoistPattern:
- '*eslint*'
- '*babel*'
Native Module Rebuilds
If native modules fail, try:
# Rebuild all native modules
pnpm rebuild
# Or reinstall
rm -rf node_modules
pnpm install
Monorepo Migration
From npm Workspaces
-
Create
pnpm-workspace.yaml:packages: - 'packages/*' -
Update internal dependencies to use workspace protocol:
{ "dependencies": { "@myorg/utils": "workspace:^" } } -
Install:
rm -rf node_modules packages/*/node_modules package-lock.json pnpm install
From Yarn Workspaces
-
Remove Yarn-specific files:
rm yarn.lock .yarnrc.yml rm -rf .yarn -
Create
pnpm-workspace.yamlmatchingworkspacesin package.json:packages: - 'packages/*' -
Update
package.json- remove Yarn workspace config if not needed:{ // Remove "workspaces" field (optional, pnpm uses pnpm-workspace.yaml) } -
Convert workspace references:
// From Yarn "@myorg/utils": "*" // To pnpm "@myorg/utils": "workspace:*"
From Lerna
pnpm can replace Lerna for most use cases:
# Lerna: run script in all packages
lerna run build
# pnpm equivalent
pnpm -r run build
# Lerna: run in specific package
lerna run build --scope=@myorg/app
# pnpm equivalent
pnpm --filter @myorg/app run build
# Lerna: publish
lerna publish
# pnpm: use changesets instead
pnpm add -Dw @changesets/cli
pnpm changeset
pnpm changeset version
pnpm publish -r
Configuration Migration
Keep only auth/registry in .npmrc; put everything else in pnpm-workspace.yaml (camelCase).
//registry.npmjs.org/:_authToken=${NPM_TOKEN}
//npm.myorg.com/:_authToken=${MYORG_TOKEN}
registries:
default: https://registry.npmjs.org/
'@myorg': https://npm.myorg.com/
autoInstallPeers: true
strictPeerDependencies: false
Scripts Migration
Most scripts work unchanged. Update pnpm-specific patterns:
{
"scripts": {
// npm: recursive scripts
"build:all": "npm run build --workspaces",
// pnpm: use -r flag
"build:all": "pnpm -r run build",
// npm: run in specific workspace
"dev:app": "npm run dev -w packages/app",
// pnpm: use --filter
"dev:app": "pnpm --filter @myorg/app run dev"
}
}
CI/CD Migration
Update CI configuration:
# Before (npm)
- run: npm ci
# After (pnpm)
- uses: pnpm/action-setup@v4
- run: pnpm install --frozen-lockfile # or: pnpm ci
Add to package.json for Corepack:
{
"packageManager": "pnpm@10.0.0"
}
Gradual Migration
For large projects, migrate gradually:
- Start with CI: Use pnpm in CI, keep npm/yarn locally
- Add pnpm-lock.yaml: Run
pnpm importto create lockfile - Test thoroughly: Ensure builds work with pnpm
- Update documentation: Update README, CONTRIBUTING
- Remove old files: Delete old lockfiles after team adoption
Rollback Plan
If migration causes issues:
# Remove pnpm files
rm -rf node_modules pnpm-lock.yaml pnpm-workspace.yaml
# Restore npm
npm install
# Or restore Yarn
yarn install
Keep old lockfile in git history for easy rollback.