Compatibility
pnpm installs from the same package.json, but it does not read npm’s lockfile. package-lock.json and npm-shrinkwrap.json are ignored: npm can install the same name@version several times with different dependencies, and its lockfile describes a flat node_modules, which pnpm’s isolated layout cannot follow.
To keep the versions you have resolved today, pnpm import generates a pnpm-lock.yaml from another package manager’s lockfile. It accepts package-lock.json, npm-shrinkwrap.json and yarn.lock.
Before you switch
- Declare workspaces first. If the project has workspaces whose dependencies you want imported, list them in a
pnpm-workspace.yamlfile before running the import. - Convert the lockfile. Run
pnpm importnext to your existingpackage-lock.jsonornpm-shrinkwrap.json.
The official page stops at the lockfile. It does not say what to do with the npm lockfile afterwards, or how to change CI and scripts that call npm.
Pitfalls
- The
node_moduleslayout changes. npm hoists every package to the root ofnode_modules, so source code can reach dependencies the project never declared. pnpm puts only the project’s direct dependencies at the root, as symlinks. - If your tooling does not work well with symlinks, set the
nodeLinkersetting tohoisted. pnpm then creates anode_modulessimilar to npm’s. - Files in
node_modules/.binare always shell files, never symlinks to JS files. If something expects a JS file there, reference the original file directly.