Topics
Recent articles

DevOps & Cloud

Fix pnpm Migration Phantom Dependency Errors

Learn how to diagnose and resolve ERR_MODULE_NOT_FOUND phantom dependency failures when transitioning from flat npm hoisting to strict pnpm in CI/CD pipelines.

Table of Contents5 sections
A flow diagram showing an undeclared package import that passes on one machine but fails in a clean pnpm CI install.
A clean install exposes imports that the project manifest never declared.

Migrating a Node.js project from package managers that use hoisted node_modules structures to strict content-addressable package managers often exposes hidden import assumptions that break continuous integration runners.

Quick solution:

pnpm add sharp

When a Node script fails with Error [ERR_MODULE_NOT_FOUND] for a package like sharp imported from scripts/medium-package.mjs after a clean continuous integration install, add the missing package to your manifest using pnpm add sharp for runtime dependencies or pnpm add -D sharp for build tools. Prerequisites include running a clean environment with a lockfile and running pnpm install --frozen-lockfile to ensure accurate dependency trees after committing updates.

Diagnosing Module Resolution Versus Build Failures

Traditional package managers often rely on node_modules layouts where dependencies of dependencies are hoisted to the root directory, allowing scripts or build tools to import packages without explicitly declaring them in the project manifest. When transitioning to pnpm, its strict symlinked and isolated structure removes this hoisting behavior. Undeclared imports that worked locally due to cached modules or ambient hoisting suddenly fail in clean continuous integration environments.

Symptom to Resolution Guide

Option When to Use It Trade-off or Failure Mode Recommendation
pnpm add <package> Runtime dependency is missing from the manifest Increases direct dependency count Explicitly declare all runtime packages in dependencies
pnpm add -D <package> Build or script tool is missing from the manifest Might bloat devDependencies if misused Use for local build scripts and automation tasks
Frozen Lockfile Update Pipeline throws lockfile mismatch errors Requires committing workspace changes Always commit lockfile updates before pushing to remote CI

Auditing and Fixing Missing Direct Imports

To prevent continuous integration failures, audit all custom scripts, build hooks, and automation tools located in directories like scripts or tools. Ensure every package imported via ES module syntax or CommonJS require statements is explicitly listed under dependencies or devDependencies in your project configuration file.

{
  "devDependencies": {
    "sharp": "*"
  }
}

After declaring the missing dependencies, update and commit the correct workspace lockfile, rerun a clean frozen install in a fresh checkout or clean workspace, and then rerun the exact failing script to verify that module resolution succeeds without relying on residual global state.

Verification and Execution Steps

Continue Exploring

You Might Also Like

View all articles
Preventing ReDoS in Frontmatter Parsers
2 min read

Preventing ReDoS in Frontmatter Parsers

Learn how to avoid regular expression denial of service vulnerabilities in lightweight Markdown frontmatter parsers by replacing complex regex with bounded line scans.

Nightly Analyst Digest from Slot Activity Logs
5 min read

Nightly Analyst Digest from Slot Activity Logs

Learn how to build a reliable scheduled digest email for high-frequency serverless cron systems, featuring local-timezone logging, fallback raw-stats reporting, and advisory-only recommendations.