pnpm

pnpm is a package manager and drop-in replacement for npm. It handles npm and JSR packages, Cargo crates, PyPI packages, tarballs, Git repositories, and local directories on Linux, macOS, Windows, and Android. Resolution, fetching, and linking happen in parallel, while package files are kept in a shared content-addressable store and linked into projects. Its workspace features support monorepos, filtering, workspace protocols, and a shared lockfile. By default, only declared direct dependencies are exposed at the root of node_modules. Since pnpm v10, install scripts are disabled unless explicitly allowed; other controls include blocking certain transitive dependencies, delaying updates, and enforcing trust policies. pnpm can audit for known vulnerabilities and verify ECDSA registry signatures. It can also install and pin Node.js per project, while its standalone installer does not require Node.js. The project describes pnpm as free, but the provided pages state no pricing, trial, refund, or free-tier limit details.

Who it is for

pnpm suits developers who manage project dependencies, especially those working with monorepos or several supported package sources. Its dependency controls and CI configuration examples may also suit teams building automated workflows.

What is good

  • Supports npm, JSR, Cargo, PyPI, Git, and local sources.
  • Workspaces include filtering and a shared lockfile.
  • Only declared direct dependencies enter root node_modules.
  • Install scripts require approval by default since pnpm v10.
  • Can install and pin Node.js per project.

What to know first

  • No free-tier limits are stated on the provided pages.
  • No trial or refund terms are stated.
  • Installation instructions list macOS, Linux, and Windows.

Freedom251 review

pnpm: the full review

pnpm combines package management with workspace, storage, and dependency-control features. It is listed as free, though the provided pages do not specify billing or free-tier terms.

Overview

pnpm is a package manager for JavaScript projects and a drop-in replacement for npm. It suits developers and teams managing shared dependencies or monorepos, particularly when disk use and install controls matter. Its shared store and workspace tooling are compelling; its security controls also ask teams to make deliberate choices about which install scripts to trust.

Package sources include npm and JSR registries, workspace packages, local directories, files, tarballs, and Git repositories. pnpm also supports formats such as Cargo crates and PyPI packages, alongside dependency resolution and lockfiles.

Rather than keeping a separate copy of package files for every project, pnpm stores them in a content-addressable store and hard-links them into projects. It resolves, fetches, and links dependencies in parallel. The project claims it can be up to 2x faster than npm and Yarn Classic, but actual performance depends on the workload.

The repository is MIT licensed except for the pnpr directory, which is source-available under the PolyForm Shield License 1.0.0. That distinction is relevant to teams assessing the project’s licensing.

Key features

Workspaces and dependency consistency

pnpm’s workspace support is built for monorepos: teams can use workspace protocols, filter by package, and share one lockfile. Dependency catalogs let a team define versions once in pnpm-workspace.yaml, reducing repeated version declarations across a workspace. This is useful for coordinated projects, though teams without a monorepo may have less reason to value the workspace features.

Isolation and install security

By default, only declared direct dependencies appear in the root node_modules directory. That makes dependency declarations more explicit, but projects relying on undeclared dependencies may need adjustment. Since pnpm v10, postinstall scripts are disabled unless explicitly allowed; packages that need those scripts require approval to run them.

Additional supply-chain controls include blocking exotic transitive dependencies, delaying updates with a default minimum release age of 1440 minutes, and enforcing trust with trustPolicy. The pnpm audit command checks known vulnerabilities and can verify ECDSA registry signatures for installed packages. These controls provide useful safeguards, but teams must decide how to configure approvals and trust policies for their dependencies.

Patching and runtime management

pn patch creates persistent patches that are reapplied on every install, giving teams a way to carry dependency changes forward. pnpm can also install and pin Node.js per project, useful when projects need a managed runtime alongside package dependencies.

Installation and automation

Installation instructions cover macOS, Linux, and Windows; a standalone script does not require Node.js. Documentation includes CI examples for AppVeyor, Azure Pipelines, Bitbucket Pipelines, CircleCI, GitHub Actions, GitLab CI, Jenkins, Semaphore, and Travis CI. The pnpm/setup GitHub Action can install pnpm and a requested runtime, run pnpm install, and cache the pnpm store.

Pricing

pnpm is free, with no free trial. No paid plans, seat counts, quotas, renewal terms, or other billing conditions are stated. Its MIT license applies to the repository except for the pnpr directory, which is source-available under the PolyForm Shield License 1.0.0.

Platforms

pnpm supports Linux, macOS, Windows, and Android. Installation instructions are provided for Linux, macOS, and Windows; Android is included among supported platforms.

Who it's for

pnpm is a strong fit for JavaScript developers and teams who want shared package storage, explicit dependency boundaries, or first-class monorepo workflows. It is also worth considering for teams that want script approvals and other dependency trust controls. Projects that need postinstall scripts should account for the approval step, and teams using dependencies that assume undeclared packages are exposed may need to revisit those assumptions.

Pros and cons

  • Pro: A shared content-addressable store and hard links reduce duplicated package files across projects.
  • Pro: Parallel resolution, fetching, and linking support the project’s speed focus.
  • Pro: Workspace filtering, one lockfile, and dependency catalogs address common coordination needs in monorepos.
  • Pro: Script approvals, trust controls, vulnerability checks, and signature verification give teams several ways to manage dependency risk.
  • Con: Postinstall scripts require explicit approval, adding a decision point for packages that depend on them.
  • Con: Exposing only declared direct dependencies by default can require changes to projects that rely on undeclared dependencies.

Alternatives

Choose npm if you want the familiar alternative and public package publishing and registry access; its free plan is aimed at public package authors. Consider uv as a free package-manager alternative. Conan is another free and open-source package manager. Yarn is a free open-source package manager with no paid plans or usage limits stated.

Choose Gradle if an open-source build system better fits your need. Cargo is a free Rust package manager and build tool. NuGet is another free package-management option, with an Apache 2.0-licensed gallery project that welcomes community contributions. Go Modules is a free alternative.

Browse Package Managers, JavaScript Package Managers, and Monorepo Management Tools for more options.

Verdict

Choose pnpm if you want an npm replacement with shared storage, strong monorepo support, and explicit dependency controls. Its main advantage is combining disk-conscious installs with workspace and security features; look elsewhere if your project depends on undeclared dependencies or you prefer install scripts to run without approval.

Compared on package managers

Free plan
Yes

Best pnpm alternatives

See all 12