pnpm 12: workspaces, catalogs, supply-chain security and release management - **name_fr:** pnpm 12 : workspaces, catalogues, sécurité de la chaîne d'approvisionnement et gestion des releases - **tl_en:** pnpm reference — workspaces, catalogs, overrides, patches, store, CI, migration, native versioning - **tl_fr:** Référence pnpm — workspaces, catalogues, overrides, patches, store, CI, migration, versioning natif - **creator:** @antfu - **type:** Agent skill - **url:** https://github.com/antfu/skills - **cat:** Developer tools - **kws:** pnpm, package manager, workspaces, monorepo, catalogs, lockfile, supply chain security, ci - **license:** MIT **Description EN:** Curated by Skill Harbor — a structured pnpm reference maintained in Anthony Fu's skills repo, based on pnpm 12.x: core (CLI commands, the camelCase `pnpm-workspace.yaml` configuration model, workspaces with filtering and the workspace protocol, the content-addressable store and node linker modes), features (catalogs, overrides, patches, aliases, `.pnpmfile.mjs` hooks, peer dependencies, config dependencies, the global virtual store, supply-chain security with `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/lockfile integrity, task orchestration, native release management with lanes, experimental multi-ecosystem Python/Cargo deps), and best practices (CI/CD, npm/Yarn→pnpm and v10→v11→v12 migration, performance). By @antfu, listed here with credit to its creator. Honest caveats: generated from the pnpm repo docs as of 2026-09-25 — pnpm v12 is a Rust rewrite keeping v11's commands, flags and lockfile format, but a handful of v12 behaviors differ (check the migration reference); the config-model change matters (settings in `pnpm-workspace.yaml`, `.npmrc` for auth only, `package.json` `pnpm` field no longer read). Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use. **Description FR:** Sélectionné par Skill Harbor — une référence pnpm structurée maintenue dans le dépôt de skills d'Anthony Fu, basée sur pnpm 12.x : core (commandes CLI, modèle de configuration camelCase `pnpm-workspace.yaml`, workspaces avec filtrage et protocole workspace, le store adressable par contenu et les modes node linker), fonctionnalités (catalogues, overrides, patches, aliases, hooks `.pnpmfile.mjs`, dépendances de pairs, dépendances de config, virtual store global, sécurité de la chaîne d'approvisionnement avec `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/intégrité du lockfile, orchestration de tâches, gestion native des releases avec lanes, dépendances multi-écosystème Python/Cargo expérimentales), et bonnes pratiques (CI/CD, migration npm/Yarn→pnpm et v10→v11→v12, performance). Crédit : @antfu. Bémols honnêtes : générée depuis la documentation du dépôt pnpm au 2026-09-25 — pnpm v12 est une réécriture Rust gardant commandes, flags et format de lockfile de v11, mais quelques comportements v12 diffèrent (voir la référence de migration) ; le changement de modèle de config compte (paramètres dans `pnpm-workspace.yaml`, `.npmrc` pour l'auth seulement, champ `pnpm` de `package.json` non lu). Découvert via skills.sh. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. **Install prompt EN:** ``` Prerequisites: Node.js; pnpm installed (v11 or v12); a JavaScript/TypeScript project or monorepo Install "pnpm 12: workspaces, catalogs, supply-chain security and release management" for me. Give my agent the structured pnpm reference — CLI, workspaces, catalogs, overrides/patches, store, supply-chain security, task orchestration, versioning, CI and migration notes — with the per-topic reference files Repository: https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Fetch the SKILL.md file (and its reference files) for the antfu-skills-pnpm skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "antfu-skills-pnpm". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install pnpm 12 and check my pnpm-workspace.yaml settings). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : Node.js ; pnpm installé (v11 ou v12) ; un projet JavaScript/TypeScript ou un monorepo Installe-moi « pnpm 12 : workspaces, catalogues, sécurité de la chaîne d'approvisionnement et gestion des releases ». Donne à mon agent la référence pnpm structurée — CLI, workspaces, catalogues, overrides/patches, store, sécurité de la chaîne, orchestration de tâches, versioning, notes CI et de migration — avec les fichiers de référence par sujet Dépôt : https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Récupère le fichier SKILL.md (et ses fichiers de référence) du skill antfu-skills-pnpm depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « antfu-skills-pnpm ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. installer pnpm 12 et vérifier mes paramètres pnpm-workspace.yaml). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
pnpm reference — workspaces, catalogs, overrides, patches, store, CI, migration, native versioning - **tl_fr:** Référence pnpm — workspaces, catalogues, overrides, patches, store, CI, migration, versioning natif - **creator:** @antfu - **type:** Agent skill - **url:** https://github.com/antfu/skills - **cat:** Developer tools - **kws:** pnpm, package manager, workspaces, monorepo, catalogs, lockfile, supply chain security, ci - **license:** MIT **Description EN:** Curated by Skill Harbor — a structured pnpm reference maintained in Anthony Fu's skills repo, based on pnpm 12.x: core (CLI commands, the camelCase `pnpm-workspace.yaml` configuration model, workspaces with filtering and the workspace protocol, the content-addressable store and node linker modes), features (catalogs, overrides, patches, aliases, `.pnpmfile.mjs` hooks, peer dependencies, config dependencies, the global virtual store, supply-chain security with `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/lockfile integrity, task orchestration, native release management with lanes, experimental multi-ecosystem Python/Cargo deps), and best practices (CI/CD, npm/Yarn→pnpm and v10→v11→v12 migration, performance). By @antfu, listed here with credit to its creator. Honest caveats: generated from the pnpm repo docs as of 2026-09-25 — pnpm v12 is a Rust rewrite keeping v11's commands, flags and lockfile format, but a handful of v12 behaviors differ (check the migration reference); the config-model change matters (settings in `pnpm-workspace.yaml`, `.npmrc` for auth only, `package.json` `pnpm` field no longer read). Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use. **Description FR:** Sélectionné par Skill Harbor — une référence pnpm structurée maintenue dans le dépôt de skills d'Anthony Fu, basée sur pnpm 12.x : core (commandes CLI, modèle de configuration camelCase `pnpm-workspace.yaml`, workspaces avec filtrage et protocole workspace, le store adressable par contenu et les modes node linker), fonctionnalités (catalogues, overrides, patches, aliases, hooks `.pnpmfile.mjs`, dépendances de pairs, dépendances de config, virtual store global, sécurité de la chaîne d'approvisionnement avec `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/intégrité du lockfile, orchestration de tâches, gestion native des releases avec lanes, dépendances multi-écosystème Python/Cargo expérimentales), et bonnes pratiques (CI/CD, migration npm/Yarn→pnpm et v10→v11→v12, performance). Crédit : @antfu. Bémols honnêtes : générée depuis la documentation du dépôt pnpm au 2026-09-25 — pnpm v12 est une réécriture Rust gardant commandes, flags et format de lockfile de v11, mais quelques comportements v12 diffèrent (voir la référence de migration) ; le changement de modèle de config compte (paramètres dans `pnpm-workspace.yaml`, `.npmrc` pour l'auth seulement, champ `pnpm` de `package.json` non lu). Découvert via skills.sh. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. **Install prompt EN:** ``` Prerequisites: Node.js; pnpm installed (v11 or v12); a JavaScript/TypeScript project or monorepo Install "pnpm 12: workspaces, catalogs, supply-chain security and release management" for me. Give my agent the structured pnpm reference — CLI, workspaces, catalogs, overrides/patches, store, supply-chain security, task orchestration, versioning, CI and migration notes — with the per-topic reference files Repository: https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Fetch the SKILL.md file (and its reference files) for the antfu-skills-pnpm skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "antfu-skills-pnpm". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install pnpm 12 and check my pnpm-workspace.yaml settings). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : Node.js ; pnpm installé (v11 ou v12) ; un projet JavaScript/TypeScript ou un monorepo Installe-moi « pnpm 12 : workspaces, catalogues, sécurité de la chaîne d'approvisionnement et gestion des releases ». Donne à mon agent la référence pnpm structurée — CLI, workspaces, catalogues, overrides/patches, store, sécurité de la chaîne, orchestration de tâches, versioning, notes CI et de migration — avec les fichiers de référence par sujet Dépôt : https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Récupère le fichier SKILL.md (et ses fichiers de référence) du skill antfu-skills-pnpm depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « antfu-skills-pnpm ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. installer pnpm 12 et vérifier mes paramètres pnpm-workspace.yaml). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- pnpm reference — workspaces, catalogs, overrides, patches, store, CI, migration, native versioning - **tl_fr:** Référence pnpm — workspaces, catalogues, overrides, patches, store, CI, migration, versioning natif - **creator:** @antfu - **type:** Agent skill - **url:** https://github.com/antfu/skills - **cat:** Developer tools - **kws:** pnpm, package manager, workspaces, monorepo, catalogs, lockfile, supply chain security, ci - **license:** MIT **Description EN:** Curated by Skill Harbor — a structured pnpm reference maintained in Anthony Fu's skills repo, based on pnpm 12.x: core (CLI commands, the camelCase `pnpm-workspace.yaml` configuration model, workspaces with filtering and the workspace protocol, the content-addressable store and node linker modes), features (catalogs, overrides, patches, aliases, `.pnpmfile.mjs` hooks, peer dependencies, config dependencies, the global virtual store, supply-chain security with `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/lockfile integrity, task orchestration, native release management with lanes, experimental multi-ecosystem Python/Cargo deps), and best practices (CI/CD, npm/Yarn→pnpm and v10→v11→v12 migration, performance). By @antfu, listed here with credit to its creator. Honest caveats: generated from the pnpm repo docs as of 2026-09-25 — pnpm v12 is a Rust rewrite keeping v11's commands, flags and lockfile format, but a handful of v12 behaviors differ (check the migration reference); the config-model change matters (settings in `pnpm-workspace.yaml`, `.npmrc` for auth only, `package.json` `pnpm` field no longer read). Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use. **Description FR:** Sélectionné par Skill Harbor — une référence pnpm structurée maintenue dans le dépôt de skills d'Anthony Fu, basée sur pnpm 12.x : core (commandes CLI, modèle de configuration camelCase `pnpm-workspace.yaml`, workspaces avec filtrage et protocole workspace, le store adressable par contenu et les modes node linker), fonctionnalités (catalogues, overrides, patches, aliases, hooks `.pnpmfile.mjs`, dépendances de pairs, dépendances de config, virtual store global, sécurité de la chaîne d'approvisionnement avec `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/intégrité du lockfile, orchestration de tâches, gestion native des releases avec lanes, dépendances multi-écosystème Python/Cargo expérimentales), et bonnes pratiques (CI/CD, migration npm/Yarn→pnpm et v10→v11→v12, performance). Crédit : @antfu. Bémols honnêtes : générée depuis la documentation du dépôt pnpm au 2026-09-25 — pnpm v12 est une réécriture Rust gardant commandes, flags et format de lockfile de v11, mais quelques comportements v12 diffèrent (voir la référence de migration) ; le changement de modèle de config compte (paramètres dans `pnpm-workspace.yaml`, `.npmrc` pour l'auth seulement, champ `pnpm` de `package.json` non lu). Découvert via skills.sh. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. **Install prompt EN:** ``` Prerequisites: Node.js; pnpm installed (v11 or v12); a JavaScript/TypeScript project or monorepo Install "pnpm 12: workspaces, catalogs, supply-chain security and release management" for me. Give my agent the structured pnpm reference — CLI, workspaces, catalogs, overrides/patches, store, supply-chain security, task orchestration, versioning, CI and migration notes — with the per-topic reference files Repository: https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Fetch the SKILL.md file (and its reference files) for the antfu-skills-pnpm skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "antfu-skills-pnpm". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install pnpm 12 and check my pnpm-workspace.yaml settings). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : Node.js ; pnpm installé (v11 ou v12) ; un projet JavaScript/TypeScript ou un monorepo Installe-moi « pnpm 12 : workspaces, catalogues, sécurité de la chaîne d'approvisionnement et gestion des releases ». Donne à mon agent la référence pnpm structurée — CLI, workspaces, catalogues, overrides/patches, store, sécurité de la chaîne, orchestration de tâches, versioning, notes CI et de migration — avec les fichiers de référence par sujet Dépôt : https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Récupère le fichier SKILL.md (et ses fichiers de référence) du skill antfu-skills-pnpm depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md et ses fichiers auxiliaires dans le répertoire des skills de l'agent, dans un dossier nommé « antfu-skills-pnpm ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. installer pnpm 12 et vérifier mes paramètres pnpm-workspace.yaml). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- Node.js; pnpm installed (v11 or v12); a JavaScript/TypeScript project or monorepo
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a structured pnpm reference maintained in Anthony Fu's skills repo, based on pnpm 12.x: core (CLI commands, the camelCase `pnpm-workspace.yaml` configuration model, workspaces with filtering and the workspace protocol, the content-addressable store and node linker modes), features (catalogs, overrides, patches, aliases, `.pnpmfile.mjs` hooks, peer dependencies, config dependencies, the global virtual store, supply-chain security with `allowBuilds`/`minimumReleaseAge`/`trustPolicy`/lockfile integrity, task orchestration, native release management with lanes, experimental multi-ecosystem Python/Cargo deps), and best practices (CI/CD, npm/Yarn→pnpm and v10→v11→v12 migration, performance). By @antfu, listed here with credit to its creator. Honest caveats: generated from the pnpm repo docs as of 2026-09-25 — pnpm v12 is a Rust rewrite keeping v11's commands, flags and lockfile format, but a handful of v12 behaviors differ (check the migration reference); the config-model change matters (settings in `pnpm-workspace.yaml`, `.npmrc` for auth only, `package.json` `pnpm` field no longer read). Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Prerequisites: Node.js; pnpm installed (v11 or v12); a JavaScript/TypeScript project or monorepo Install "pnpm 12: workspaces, catalogs, supply-chain security and release management" for me. Give my agent the structured pnpm reference — CLI, workspaces, catalogs, overrides/patches, store, supply-chain security, task orchestration, versioning, CI and migration notes — with the per-topic reference files Repository: https://github.com/antfu/skills/blob/main/skills/pnpm/SKILL.md 1. Fetch the SKILL.md file (and its reference files) for the antfu-skills-pnpm skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "antfu-skills-pnpm". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install pnpm 12 and check my pnpm-workspace.yaml settings). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.