pnpm update

命令別名:up, upgrade

pnpm update 將套件更新至其允許範圍內的最新版本。

當不使用其他引數時,更新所有相依性。

TL;DR#

命令效果
pnpm up依 package.json 中指定的範圍,將所有相依性更新至最新版
pnpm up --latestUpdates all dependencies to their latest versions
pnpm up foo@2將 foo 更新到 v2 的最新版
pnpm up "@babel/*"更新 @babel 底下的所有相依性

What an update writes#

Besides moving pnpm-lock.yaml to the newly resolved versions, pnpm update writes the new range back to the place the dependency is declared:

  • In package.json, the range is moved onto the resolved version while the operator the dependency already declared is kept, so ^1.1.0 stays a caret range.
  • A dependency declared through the catalog: protocol is not rewritten in package.json. The catalog entry it points at is updated instead, in pnpm-workspace.yaml.
  • A dependency declared through a dist-tag, such as "foo": "latest", keeps tracking the tag. The tag stays in package.json and only the lockfile moves to the version behind it — with --latest as well.

Pass --no-save to update the lockfile only and leave the declared ranges alone.

Selecting dependencies with patterns#

You can use patterns to update specific dependencies.

Update all babel packages:

pnpm update "@babel/*"

Update all dependencies, except webpack:

pnpm update "\!webpack"

Patterns may also be combined, so the next command will update all babel packages, except core:

pnpm update "@babel/*" "\!@babel/core"

Updating GitHub Actions#

Added in: v11.16.0

pnpm outdated can check the GitHub Actions referenced by the repository's workflow files for updates, and pnpm update can update them. This is opt-in for every command: pass --include-github-actions, or set update.githubActions to true in pnpm-workspace.yaml to enable it by default.

Updated actions are pinned to exact commit hashes, with their release tags preserved in comments:

- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0

Checking for updates runs git ls-remote against every referenced repository. Actions whose refs cannot be read — for example, an action in a private repository — are skipped with a warning. If the actions are hosted on a different GitHub server (such as a GitHub Enterprise Server), set update.githubActionsServer (added in v11.17.0).

Options#

--recursive, -r#

對除了 node_modules 以外所有包含 package.json 的子目錄並行執行更新。

使用示例:

pnpm --recursive update
# updates all packages up to 100 subdirectories in depth
pnpm --recursive update --depth 100
# update typescript to the latest version in every package
pnpm --recursive update typescript@latest

--latest, -L#

Update the dependencies to their latest stable version as determined by their latest tags (potentially upgrading the packages across major versions) as long as the version range specified in package.json is lower than the latest tag (i.e. it will not downgrade prereleases).

--global, -g#

Update global packages.

--workspace#

Tries to link all packages from the workspace. Versions are updated to match the versions of packages inside the workspace.

If specific packages are updated, the command will fail if any of the updated dependencies are not found inside the workspace. For instance, the following command fails if express is not a workspace package:

pnpm up -r --workspace express

--prod, -P#

僅更新位於 dependencies 與 optionalDependencies 中的套件。

--dev, -D#

僅更新位於 devDependencies 的套件。

--no-optional#

不更新 optionalDependencies 中的套件。

--interactive, -i#

列出過時的相依套件,並從中選擇要更新的。

Since v11.21.0, combined with --global, each isolated install group is presented as one selectable item: packages that share a global installation update together as a unit.

--no-save#

Don't update the ranges in package.json.

--changeset#

Added in: v11.16.0

After the update completes, write a change intent — a changesets-compatible .changeset/*.md file — declaring a patch bump for every workspace package whose dependencies or optionalDependencies were changed by the update, and a major bump when its peerDependencies changed. Packages that consume an updated catalog entry via the catalog: protocol are included. Private packages, packages without a name, and packages listed in the ignore array of .changeset/config.json are skipped. If .changeset/config.json does not exist, a warning is printed and no changeset is generated.

Set update.changeset to true in pnpm-workspace.yaml to enable this behavior by default, and use --no-changeset to override the setting for one update.

--include-github-actions#

Added in: v11.16.0

Also update the GitHub Actions referenced by the repository's workflow files. See Updating GitHub Actions.

--filter <package_selector>#

Read more about filtering.