TypeScript Package Manager Skill
An expert skill for managing TypeScript projects with comprehensive knowledge of modern package management tools and ecosystem best practices.
When to Use This Skill
- Setting up or configuring package managers (npm, yarn, pnpm, bun, deno)
- Managing project dependencies and resolving conflicts
- Optimizing package.json configuration
- Working with monorepos and workspaces
- Troubleshooting installation or dependency issues
- Configuring package scripts and build pipelines
- Understanding lock files and version constraints
- Integrating package managers with build tools
- Migrating between package managers
- Performance optimization of package operations
Prerequisites
- Node.js environment (for npm, yarn, pnpm, bun)
- Basic understanding of TypeScript/JavaScript projects
- Terminal/command line access
- Understanding of semantic versioning (semver)
Shorthand Keywords
Keywords to trigger this skill quickly:
openPrompt = ["typescript-package-manager", "ts-pkg", "pkg-manager"]
Use these shorthand commands for quick invocation:
ts-pkg --install <package>
pkg-manager --compare-tools
ts-pkg migrate to pnpm
pkg-manager --optimize workspace
Core Capabilities
Package Manager Expertise
This skill provides deep knowledge across all major JavaScript/TypeScript package managers:
- npm: The default Node.js package manager, widely used and battle-tested
- yarn: Fast, reliable package manager with enhanced features
- pnpm: Disk-space efficient with strict dependency isolation
- bun: Ultra-fast all-in-one toolkit with native package management
- deno: Secure-by-default runtime with built-in tooling
Dependency Management
- Installing, updating, and removing dependencies
- Managing dev dependencies vs production dependencies
- Understanding peer dependencies and optional dependencies
- Resolving version conflicts and compatibility issues
- Audit and security vulnerability management
- Dependency deduplication and optimization
Configuration and Optimization
- package.json structure and best practices
- Lock file management (package-lock.json, yarn.lock, pnpm-lock.yaml)
- Workspace and monorepo configuration
- Scripts and lifecycle hooks
- Registry configuration and private packages
- CI/CD integration
Ecosystem Integration
- TypeScript compiler (tsc) integration with package managers
- Build tool configuration (Vite, webpack, esbuild, Rollup, Turbopack)
- Testing framework setup (Vitest, Jest, Mocha)
- Linting and formatting tools (ESLint, Prettier)
- Development server configuration and hot reload
- CI/CD pipeline optimization
Key Concepts
Semantic Versioning (semver)
Understanding version constraints in package.json:
- ^1.2.3 (caret): >=1.2.3 <2.0.0 - Allows minor and patch updates (recommended)
- ~1.2.3 (tilde): >=1.2.3 <1.3.0 - Allows only patch updates
- 1.2.3 (exact): Exact version only
- >=1.2.3 <2.0.0 (range): Custom version range
- latest: Always use latest version (dangerous, not recommended)
Lock Files
Lock files ensure reproducible installations across environments:
- package-lock.json (npm): JSON format, exact dependency tree
- yarn.lock (yarn): YAML-like format, deterministic resolution
- pnpm-lock.yaml (pnpm): YAML format with content-addressable storage
- bun.lockb (bun): Binary format for fast parsing
Best Practice: Always commit lock files to version control.
Workspaces (Monorepos)
Manage multiple packages in a single repository:
{
"workspaces": ["packages/*", "apps/*"]
}
Benefits:
- Shared dependencies across packages
- Cross-package development and testing
- Unified versioning and release coordination
- Simplified dependency management
Best Practices
Choose the Right Tool: Understand trade-offs between package managers for your project needs
- npm: Maximum compatibility, widest ecosystem support
- yarn: Enhanced features, good monorepo support
- pnpm: Best disk space efficiency, strict dependencies
- bun: Maximum speed, all-in-one tooling
- deno: Security-first, URL-based imports
Lock File Discipline: Always commit lock files to ensure reproducible builds across environments
Semantic Versioning: Use appropriate version constraints
- Use
^ (caret) for most dependencies (recommended)
- Use
~ (tilde) for conservative updates
- Use exact versions only when necessary
Security First: Regularly audit dependencies for vulnerabilities
npm audit # npm
yarn audit # yarn
pnpm audit # pnpm
bun pm audit # bun
Workspace Optimization: Leverage workspaces for monorepo efficiency and shared dependencies
Script Consistency: Use cross-platform compatible scripts (avoid shell-specific commands)
Minimal Dependencies: Avoid unnecessary packages to reduce complexity, security surface, and bundle size
Documentation: Document package manager choice, special configurations, and setup instructions in README.md
CI/CD Optimization: Use frozen lockfiles in CI for deterministic builds
npm ci # npm
yarn install --frozen-lockfile # yarn
pnpm install --frozen-lockfile # pnpm
bun install --frozen-lockfile # bun
Version Management: Use packageManager field in package.json to enforce consistency
{
"packageManager": "pnpm@8.15.0"
}
Choosing the Right Package Manager
Decision Factors
npm (Default Choice)
- ✅ Maximum compatibility and ecosystem support
- ✅ Default with Node.js, no additional setup
- ✅ Well-tested and mature
- ❌ Slower than alternatives
- ❌ Less disk-efficient
yarn (Enhanced Features)
- ✅ Good performance and caching
- ✅ Excellent monorepo/workspace support
- ✅ Plug'n'Play mode (Berry) for zero-installs
- ❌ Classic vs Berry version confusion
- ❌ Plug'n'Play requires IDE setup
pnpm (Recommended for Most Projects)
- ✅ 60-70% disk space savings
- ✅ 2-3x faster than npm
- ✅ Strict dependency isolation prevents phantom dependencies
- ✅ Excellent monorepo support
- ❌ May expose hidden dependency issues
bun (Cutting Edge)
- ✅ Blazing fast (5-10x faster than npm)
- ✅ All-in-one: runtime, bundler, test runner
- ✅ Native TypeScript support
- ❌ Newer and less mature
- ❌ Some npm package incompatibilities
deno (Security-First)
- ✅ Secure by default with explicit permissions
- ✅ Native TypeScript support
- ✅ No package.json or node_modules
- ❌ Different paradigm (URL-based imports)
- ❌ Smaller ecosystem than npm
Quick Recommendation
- New TypeScript project: pnpm or bun
- Existing project: Keep current manager unless migrating for specific benefits
- Monorepo: pnpm or yarn (berry)
- Maximum compatibility: npm
- Security-critical: deno or pnpm
Common Tasks
Installing Dependencies
# npm
npm install
# yarn
yarn install
# pnpm
pnpm install
# bun
bun install
Adding New Dependencies
# Production dependency
npm install package-name
yarn add package-name
pnpm add package-name
bun add package-name
# Development dependency
npm install --save-dev package-name
yarn add --dev package-name
pnpm add --save-dev package-name
bun add --dev package-name
Running Scripts
# All package managers support npm scripts
npm run script-name
yarn script-name
pnpm script-name
bun run script-name
Troubleshooting
Common Issues
Installation Failures:
- Clear cache and retry
- Delete node_modules and lock file, reinstall
- Check for incompatible peer dependencies
- Verify Node.js version compatibility
Version Conflicts:
- Use resolutions/overrides in package.json
- Upgrade conflicting dependencies
- Consider using pnpm for better isolation
Performance Issues:
- Use pnpm or bun for faster operations
- Enable caching mechanisms
- Optimize workspace configuration
Lock File Conflicts:
- Resolve merge conflicts carefully
- Regenerate lock file if corrupted
- Ensure team uses same package manager
References
See the references/ folder for detailed documentation:
- package-management.md - Comprehensive guide to JavaScript/TypeScript package managers including npm, yarn, pnpm, bun, deno, with concepts, version management, security, and best practices
- integration-with-build-tools.md - Complete guide to integrating package managers with Vite, webpack, esbuild, Rollup, TypeScript compiler (tsc), and CI/CD pipelines
Scripts
See the scripts/ folder for workflow guides and automation:
- npm-workflow.md / npm-workflow.js - Complete npm workflow from initialization to publishing
- yarn-workflow.md - Complete yarn workflow covering Classic (1.x) and Berry (3.x+) versions
- pnpm-workflow.md - Complete pnpm workflow with monorepo and workspace features
- bun-workflow.md / bun-workflow.js - Complete bun workflow for ultra-fast package management
- health-check.md / health-check.js - Package manager health check and diagnostics scripts
Assets
See the assets/ folder for templates and reference materials:
- package-manager-comparison.md - Detailed comparison matrix, benchmarks, and decision tree for choosing package managers
- package-json-template.md - Production-ready package.json template with field-by-field explanations and best practices
1---2name: typescript-package-manager3description: Expert 10x Software engineer specializing in TypeScript with deep knowledge of all popular package management tools including npm, yarn, pnpm, bun, and deno. Use when asked to configure package managers, manage dependencies, set up workspaces, resolve package conflicts, optimize package.json files, troubleshoot installation issues, or work with monorepos. Expertise covers package scripts, version management, lock files, and build tool integration.4---56# TypeScript Package Manager Skill78An expert skill for managing TypeScript projects with comprehensive knowledge of modern package management tools and ecosystem best practices.910## When to Use This Skill1112- Setting up or configuring package managers (npm, yarn, pnpm, bun, deno)13- Managing project dependencies and resolving conflicts14- Optimizing package.json configuration15- Working with monorepos and workspaces16- Troubleshooting installation or dependency issues17- Configuring package scripts and build pipelines18- Understanding lock files and version constraints19- Integrating package managers with build tools20- Migrating between package managers21- Performance optimization of package operations2223## Prerequisites2425- Node.js environment (for npm, yarn, pnpm, bun)26- Basic understanding of TypeScript/JavaScript projects27- Terminal/command line access28- Understanding of semantic versioning (semver)2930## Shorthand Keywords3132Keywords to trigger this skill quickly:3334```javascript35openPrompt = ["typescript-package-manager", "ts-pkg", "pkg-manager"]36```3738Use these shorthand commands for quick invocation:3940- `ts-pkg --install <package>`41- `pkg-manager --compare-tools`42- `ts-pkg migrate to pnpm`43- `pkg-manager --optimize workspace`4445## Core Capabilities4647### Package Manager Expertise4849This skill provides deep knowledge across all major JavaScript/TypeScript package managers:5051- **npm**: The default Node.js package manager, widely used and battle-tested52- **yarn**: Fast, reliable package manager with enhanced features53- **pnpm**: Disk-space efficient with strict dependency isolation54- **bun**: Ultra-fast all-in-one toolkit with native package management55- **deno**: Secure-by-default runtime with built-in tooling5657### Dependency Management5859- Installing, updating, and removing dependencies60- Managing dev dependencies vs production dependencies61- Understanding peer dependencies and optional dependencies62- Resolving version conflicts and compatibility issues63- Audit and security vulnerability management64- Dependency deduplication and optimization6566### Configuration and Optimization6768- package.json structure and best practices69- Lock file management (package-lock.json, yarn.lock, pnpm-lock.yaml)70- Workspace and monorepo configuration71- Scripts and lifecycle hooks72- Registry configuration and private packages73- CI/CD integration7475### Ecosystem Integration7677- TypeScript compiler (tsc) integration with package managers78- Build tool configuration (Vite, webpack, esbuild, Rollup, Turbopack)79- Testing framework setup (Vitest, Jest, Mocha)80- Linting and formatting tools (ESLint, Prettier)81- Development server configuration and hot reload82- CI/CD pipeline optimization8384## Key Concepts8586### Semantic Versioning (semver)8788Understanding version constraints in package.json:8990- **^1.2.3** (caret): >=1.2.3 <2.0.0 - Allows minor and patch updates (recommended)91- **~1.2.3** (tilde): >=1.2.3 <1.3.0 - Allows only patch updates92- **1.2.3** (exact): Exact version only93- **>=1.2.3 <2.0.0** (range): Custom version range94- **latest**: Always use latest version (dangerous, not recommended)9596### Lock Files9798Lock files ensure reproducible installations across environments:99100- **package-lock.json** (npm): JSON format, exact dependency tree101- **yarn.lock** (yarn): YAML-like format, deterministic resolution102- **pnpm-lock.yaml** (pnpm): YAML format with content-addressable storage103- **bun.lockb** (bun): Binary format for fast parsing104105**Best Practice:** Always commit lock files to version control.106107### Workspaces (Monorepos)108109Manage multiple packages in a single repository:110111```json112{113 "workspaces": ["packages/*", "apps/*"]114}115```116117**Benefits:**118- Shared dependencies across packages119- Cross-package development and testing120- Unified versioning and release coordination121- Simplified dependency management122123## Best Practices1241251. **Choose the Right Tool**: Understand trade-offs between package managers for your project needs126 - npm: Maximum compatibility, widest ecosystem support127 - yarn: Enhanced features, good monorepo support128 - pnpm: Best disk space efficiency, strict dependencies129 - bun: Maximum speed, all-in-one tooling130 - deno: Security-first, URL-based imports1311322. **Lock File Discipline**: Always commit lock files to ensure reproducible builds across environments1331343. **Semantic Versioning**: Use appropriate version constraints135 - Use `^` (caret) for most dependencies (recommended)136 - Use `~` (tilde) for conservative updates137 - Use exact versions only when necessary1381394. **Security First**: Regularly audit dependencies for vulnerabilities140 ```bash141 npm audit # npm142 yarn audit # yarn143 pnpm audit # pnpm144 bun pm audit # bun145 ```1461475. **Workspace Optimization**: Leverage workspaces for monorepo efficiency and shared dependencies1481496. **Script Consistency**: Use cross-platform compatible scripts (avoid shell-specific commands)1501517. **Minimal Dependencies**: Avoid unnecessary packages to reduce complexity, security surface, and bundle size1521538. **Documentation**: Document package manager choice, special configurations, and setup instructions in README.md1541559. **CI/CD Optimization**: Use frozen lockfiles in CI for deterministic builds156 ```bash157 npm ci # npm158 yarn install --frozen-lockfile # yarn159 pnpm install --frozen-lockfile # pnpm160 bun install --frozen-lockfile # bun161 ```16216310. **Version Management**: Use `packageManager` field in package.json to enforce consistency164 ```json165 {166 "packageManager": "pnpm@8.15.0"167 }168 ```169170## Choosing the Right Package Manager171172### Decision Factors173174**npm (Default Choice)**175- ✅ Maximum compatibility and ecosystem support176- ✅ Default with Node.js, no additional setup177- ✅ Well-tested and mature178- ❌ Slower than alternatives179- ❌ Less disk-efficient180181**yarn (Enhanced Features)**182- ✅ Good performance and caching183- ✅ Excellent monorepo/workspace support184- ✅ Plug'n'Play mode (Berry) for zero-installs185- ❌ Classic vs Berry version confusion186- ❌ Plug'n'Play requires IDE setup187188**pnpm (Recommended for Most Projects)**189- ✅ 60-70% disk space savings190- ✅ 2-3x faster than npm191- ✅ Strict dependency isolation prevents phantom dependencies192- ✅ Excellent monorepo support193- ❌ May expose hidden dependency issues194195**bun (Cutting Edge)**196- ✅ Blazing fast (5-10x faster than npm)197- ✅ All-in-one: runtime, bundler, test runner198- ✅ Native TypeScript support199- ❌ Newer and less mature200- ❌ Some npm package incompatibilities201202**deno (Security-First)**203- ✅ Secure by default with explicit permissions204- ✅ Native TypeScript support205- ✅ No package.json or node_modules206- ❌ Different paradigm (URL-based imports)207- ❌ Smaller ecosystem than npm208209### Quick Recommendation210211- **New TypeScript project**: pnpm or bun212- **Existing project**: Keep current manager unless migrating for specific benefits213- **Monorepo**: pnpm or yarn (berry)214- **Maximum compatibility**: npm215- **Security-critical**: deno or pnpm216217## Common Tasks218219### Installing Dependencies220221```bash222# npm223npm install224225# yarn226yarn install227228# pnpm229pnpm install230231# bun232bun install233```234235### Adding New Dependencies236237```bash238# Production dependency239npm install package-name240yarn add package-name241pnpm add package-name242bun add package-name243244# Development dependency245npm install --save-dev package-name246yarn add --dev package-name247pnpm add --save-dev package-name248bun add --dev package-name249```250251### Running Scripts252253```bash254# All package managers support npm scripts255npm run script-name256yarn script-name257pnpm script-name258bun run script-name259```260261## Troubleshooting262263### Common Issues264265**Installation Failures**:266- Clear cache and retry267- Delete node_modules and lock file, reinstall268- Check for incompatible peer dependencies269- Verify Node.js version compatibility270271**Version Conflicts**:272- Use resolutions/overrides in package.json273- Upgrade conflicting dependencies274- Consider using pnpm for better isolation275276**Performance Issues**:277- Use pnpm or bun for faster operations278- Enable caching mechanisms279- Optimize workspace configuration280281**Lock File Conflicts**:282- Resolve merge conflicts carefully283- Regenerate lock file if corrupted284- Ensure team uses same package manager285286## References287288See the `references/` folder for detailed documentation:289290- **package-management.md** - Comprehensive guide to JavaScript/TypeScript package managers including npm, yarn, pnpm, bun, deno, with concepts, version management, security, and best practices291- **integration-with-build-tools.md** - Complete guide to integrating package managers with Vite, webpack, esbuild, Rollup, TypeScript compiler (tsc), and CI/CD pipelines292293## Scripts294295See the `scripts/` folder for workflow guides and automation:296297- **npm-workflow.md** / **npm-workflow.js** - Complete npm workflow from initialization to publishing298- **yarn-workflow.md** - Complete yarn workflow covering Classic (1.x) and Berry (3.x+) versions299- **pnpm-workflow.md** - Complete pnpm workflow with monorepo and workspace features300- **bun-workflow.md** / **bun-workflow.js** - Complete bun workflow for ultra-fast package management301- **health-check.md** / **health-check.js** - Package manager health check and diagnostics scripts302303## Assets304305See the `assets/` folder for templates and reference materials:306307- **package-manager-comparison.md** - Detailed comparison matrix, benchmarks, and decision tree for choosing package managers308- **package-json-template.md** - Production-ready package.json template with field-by-field explanations and best practices