pnpm

Android only

9.2No. 1 of 93
in Package Managers
  • Recognised40% of the score97
  • Phone app26% of the score100
  • Documented20% of the score100
  • Free plan14% of the score30
Free plan
No
Runs on
Android, Linux, Mac, Windows

Summary

pnpm is a package manager and drop-in replacement for npm, available for Linux, macOS, Windows, and Android. It handles npm and JSR packages, Cargo crates, PyPI packages, tarballs, Git repositories, and local directories. Dependency resolution, fetching, and linking run in parallel, while package files are kept in a shared content-addressable store and linked into projects. Workspaces support monorepos with filtering, workspace protocols, and a shared lockfile. By default, only declared direct dependencies appear at the root of node_modules. Since pnpm v10, install scripts are disabled unless explicitly allowed. Other controls include blocking certain transitive dependencies, delaying updates, and applying trust policies; pnpm can also audit for known vulnerabilities and verify registry signatures. It can install and pin Node.js per project, and its standalone installer does not require Node.js. pnpm is free. The provided pages state no pricing, billing, trial, refund, or free-tier limit details.

Who it is for

pnpm suits developers managing dependencies for projects, particularly monorepos that need workspace filtering and a shared lockfile. It also supports teams that want controls over install scripts and dependency trust.

What is good

  • Works on Linux, macOS, Windows, and Android
  • Supports multiple registries and package sources
  • Workspace tools include filtering and a shared lockfile
  • Install scripts require approval by default since v10
  • Can audit vulnerabilities and verify registry signatures

What to know first

  • No trial or refund terms are stated
  • No free-tier limits are stated
  • Standalone installation instructions cover macOS, Linux, and Windows

Samsung Mobile US Press review

pnpm: the full review

pnpm combines package management with workspace features, dependency isolation, and supply-chain controls. It is free, though the provided pages do not specify billing or plan limits.

Overview

pnpm is a package manager for JavaScript projects, built as a drop-in replacement for npm. It is best suited to teams managing multiple related packages or looking to reduce duplicated dependency storage. Its strongest case is the combination of workspace tooling, dependency isolation, and install-time controls.

Package files are kept in a shared content-addressable store and hard-linked into projects, while resolution, fetching, and linking run in parallel. That design can save disk space across projects and streamline installs; the project claims speeds of up to 2x npm and Yarn Classic, though results depend on the workload. pnpm handles npm and JSR registries, workspaces, local files, tarballs, Git repositories, and additional formats including Cargo crates and PyPI packages.

The repository is MIT-licensed except for the pnpr directory, which uses the PolyForm Shield License 1.0.0. That distinction is worth reviewing for organizations assessing licensing.

Key features

Workspaces and dependency consistency

For monorepos, pnpm offers workspace protocols, package filtering, and a shared lockfile. Dependency catalogs define versions centrally in pnpm-workspace.yaml, reducing repeated version declarations across packages. These features make pnpm a particularly practical fit for repositories that need coordinated dependency management; for a single small project, they may matter less.

Isolation and install security

By default, only declared direct dependencies appear at the root of node_modules, helping expose accidental reliance on undeclared packages. Since pnpm v10, package postinstall scripts are disabled unless explicitly approved. Teams can also block unusual transitive dependencies, delay updates with a default minimum release age of 1440 minutes, and apply trustPolicy. These controls provide useful safeguards, but require teams to decide which packages and scripts to trust.

Patching and runtime management

pn patch creates persistent patches that are reapplied on each install, useful when a project needs a durable change to a dependency. pnpm can also install and pin Node.js per project, helping teams keep runtime choices aligned.

Audit, signatures, and automation

pnpm audit checks for known vulnerabilities and can verify ECDSA registry signatures for installed packages. Documentation includes CI configuration examples for services including GitHub Actions, GitLab CI, Jenkins, and Azure Pipelines. The pnpm setup action for GitHub Actions can install pnpm and a requested runtime, run installation, and cache the pnpm store. Those integrations suit automated builds, though teams using other CI systems may need to adapt their setup.

Pricing

pnpm is free, with no free trial. The project offers no paid plan terms to weigh against the free option. There is no published plan breakdown or stated quota, seat cap, renewal term, or refund policy, so teams should not assume a particular service-level or billing arrangement. The core repository is MIT-licensed, subject to the pnpr licensing exception noted above.

Platforms

pnpm supports Linux, macOS, Windows, and Android. Installation instructions cover macOS, Linux, and Windows; a standalone installer script does not require Node.js, which is useful when setting up the package manager before a runtime is present.

Who it's for

pnpm is a strong choice for JavaScript teams with monorepos, shared dependencies, or a preference for stricter dependency boundaries. Its content-addressable store is also appealing to developers maintaining several projects that use overlapping packages. Teams that need a narrowly scoped tool for another language may prefer a package manager built specifically for that ecosystem, while projects with no workspace or isolation needs may have less reason to switch from their current npm-based workflow.

Pros and cons

  • Pro: A shared store with hard-linked project files can limit duplicated package storage across projects.
  • Pro: Workspace filtering and a shared lockfile give monorepo teams concrete ways to coordinate packages.
  • Pro: Default dependency isolation and approval for install scripts offer safeguards against undeclared dependencies and unwanted script execution.
  • Pro: Persistent patches, runtime pinning, audit checks, and registry signature verification cover needs beyond basic installation.
  • Con: The workspace and supply-chain controls may add decisions and process for a simple project that does not need them.
  • Con: The speed advantage is a project claim rather than a guarantee for every repository or installation pattern.
  • Con: The pnpr directory has a different license from the rest of the repository, which adds a licensing check for some adopters.

Alternatives

Choose npm if you want the established JavaScript package manager and public registry publishing; its free plan covers public package publishing and use, with paid plans also offered. Yarn is another free package-manager option if you want an alternative in the same general category without stated paid plans or usage limits.

For projects in other ecosystems, uv is a free open-source Python package manager, while Cargo is a free Rust package manager and build tool. Conan is a free, open-source choice for C and C++ package and dependency management. Go Modules, vcpkg, and Gradle are other free options to consider.

Browse Package Managers, JavaScript Package Managers, or Monorepo Management Tools for more options by category.

Verdict

Choose pnpm if your JavaScript work benefits from shared dependency storage, coordinated monorepos, and explicit install controls. Those capabilities make it more compelling than a basic npm replacement for teams with multiple packages or tighter dependency policies. Look elsewhere if you need a language-specific manager, or if the workspace and security controls would add complexity without solving a real problem.

Compared on package managers

Free plan
Yespnpm.io

Facts

Package formats
npm packages, JSR packages, Cargo crates, PyPI packages, tarballs, Git repositories, local directoriespnpm.io · 21 Sept 2026
Supported platforms
Linux, macOS, Windows, Androidpnpm.io · 21 Sept 2026
Dependency resolution
Yespnpm.io · 21 Sept 2026
Lockfile support
Yespnpm.io · 21 Sept 2026
Workspace support
Yespnpm.io · 21 Sept 2026
Private registry auth
Yespnpm.io · 21 Sept 2026
Offline installation
Yespnpm.io · 21 Sept 2026
Pricing page status
The provided pricing page returned Page Not Found.pnpm.io · 28 Sept 2026
Billing details
No pricing or billing details are stated on the provided pages.pnpm.io · 28 Sept 2026
Free tier
No free-tier plan or limits are stated on the provided pages.pnpm.io · 28 Sept 2026
Trial and refund
No trial or refund terms are stated on the provided pages.pnpm.io · 28 Sept 2026
Package manager type
pnpm is a drop-in replacement for npm.pnpm.io · 28 Sept 2026
Install speed
Resolution, fetching, and linking happen in parallel.pnpm.io · 28 Sept 2026
Disk efficiency
Files are hard-linked from one content-addressable store.pnpm.io · 28 Sept 2026
Workspace features
Workspaces support monorepos, filtering, and one lockfile.pnpm.io · 28 Sept 2026
Dependency catalogs
Catalogs define dependency versions once in pnpm-workspace.yaml.pnpm.io · 28 Sept 2026
Strict dependencies
Only declared dependencies enter the root node_modules directory.pnpm.io · 28 Sept 2026
Build script security
Install scripts require approval for packages allowed to execute them.pnpm.io · 28 Sept 2026
Dependency patching
pn patch creates persistent patches reapplied on every install.pnpm.io · 28 Sept 2026
Runtime management
pnpm can install and pin Node.js per project.pnpm.io · 28 Sept 2026
Installation platforms
Installation instructions are provided for macOS, Linux, and Windows.pnpm.io · 28 Sept 2026
Standalone installation
The standalone script does not require Node.js.pnpm.io · 28 Sept 2026
Registry integration
pnpm supports JSR registry integration, and pnpr is listed as a registry server.pnpm.io · 28 Sept 2026
Community support
Community channels include X, YouTube, Reddit, Bluesky, and Discord.pnpm.io · 28 Sept 2026
Project ownership
The site credits contributors from 2015 through 2026.pnpm.io · 28 Sept 2026
Open-source users
Listed OSS projects using pnpm include Next.js, Vite, Vue, and Angular.pnpm.io · 28 Sept 2026
What it does
pnpm is a fast, disk-space-efficient package manager and a drop-in replacement for npm.pnpm.io · 28 Sept 2026
Content-addressable storage
pnpm stores package files in a single content-addressable store and links them into projects.pnpm.io · 28 Sept 2026
Installation speed
pnpm resolves, fetches, and links dependencies in parallel and describes its installation process as significantly faster than the traditional approach.pnpm.io · 28 Sept 2026
Monorepos
pnpm provides first-class workspace support for monorepos, including workspace protocols, filtering, and a shared lockfile.pnpm.io · 28 Sept 2026
Dependency isolation
By default, pnpm exposes only declared direct dependencies in the root of node_modules.pnpm.io · 28 Sept 2026
Security defaults
Since pnpm v10, dependency postinstall scripts are disabled automatically unless explicitly allowed.pnpm.io · 28 Sept 2026
Supply-chain controls
pnpm supports blocking exotic transitive dependencies, delaying updates with a default minimum release age of 1440 minutes, and enforcing trust with trustPolicy.pnpm.io · 28 Sept 2026
Audit and signatures
pnpm audit can check known vulnerabilities and verify ECDSA registry signatures for installed packages.pnpm.io · 28 Sept 2026
CI integrations
The documentation provides configuration examples for AppVeyor, Azure Pipelines, Bitbucket Pipelines, CircleCI, GitHub Actions, GitLab CI, Jenkins, Semaphore, and Travis CI.pnpm.io · 28 Sept 2026
GitHub Actions integration
The pnpm/setup action installs pnpm, can install the requested runtime, runs pnpm install, and can cache the pnpm store.pnpm.io · 28 Sept 2026
Supported package sources
pnpm supports npm and JSR registries, workspace packages, local files, remote tarballs, and Git repositories.pnpm.io · 28 Sept 2026
License
The pnpm repository is MIT licensed except for the pnpr directory, which is source-available under the PolyForm Shield License 1.0.0.github.com · 28 Sept 2026
Performance claim
The project README says pnpm is up to 2x faster than npm and Yarn Classic.github.com · 28 Sept 2026
Installation limit
pnpm 12 requires Node.js 22.13 or newer when installed through npm, while the standalone executable does not require Node.js after installation.pnpm.io · 28 Sept 2026
Purpose
pnpm is a drop-in replacement for npm that manages project dependencies.pnpm.io · 30 Sept 2026
Disk use
pnpm stores package files in a shared content-addressable store and hard-links them into project node_modules.pnpm.io · 30 Sept 2026
Build safety
pnpm disables automatic execution of dependency postinstall scripts and recommends explicitly allowing trusted builds.pnpm.io · 30 Sept 2026
Release delay
The minimumReleaseAge setting defaults to 1440 minutes, delaying installation of newly published package versions for one day.pnpm.io · 30 Sept 2026
Integrations
The CI guide provides setup examples for systems including AppVeyor, Azure Pipelines, Bitbucket Pipelines, and CircleCI.pnpm.io · 30 Sept 2026
Feature set
The feature comparison lists dependency patching, catalogs, JSR registry support, SBOM generation, license listing, and build script security.pnpm.io · 30 Sept 2026
Release workflow limit
The workspace documentation says pnpm does not currently provide a built-in solution for versioning workspace packages and points to Changesets and Rush.pnpm.io · 30 Sept 2026
Installation requirement
pnpm 12 is a native executable that does not require Node.js after installation; installing it through npm requires Node.js 22.13 or newer.pnpm.io · 30 Sept 2026
Platform support
pnpm 12 provides prebuilt binaries for Linux, macOS, Windows, FreeBSD, and Android, with a JavaScript pnpm 11 fallback for targets without a binary.pnpm.io · 30 Sept 2026

Best pnpm alternatives

See all 12

Where it ranks on Samsung Mobile US Press

Is pnpm yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources