Introduction to Pastoralist
Pastoralist keeps dependency overrides explainable, current, and removable
Pastoralist keeps dependency overrides explainable, current, and removable
Pastoralist tracks your dependency overrides: why they're there, which packages need them, and when you can remove them.
Pastoralist works with npm and Bun overrides, pnpm pnpm.overrides, and Yarn
resolutions. It can also tie security fixes, patch files, workspace packages,
and CI checks to the same record.
Overrides usually start as real fixes: a CVE patch, a compatibility pin, a fork, or a transitive dependency workaround.
{ "overrides": { "lodash": "4.17.21" }}Months later, the reason may not be clear. Was it a security fix? A transitive bug? Which packages still need it? Can it be removed? With Pastoralist, the override sets the version, and the appendix holds the context.
{ "overrides": { "lodash": "4.17.21" }, "pastoralist": { "appendix": { "[email protected]": { "dependents": { "web-app": "lodash@^4.17.20", "admin-ui": "lodash@^4.17.19" }, "ledger": { "addedDate": "2026-05-06T00:00:00.000Z", "reason": "Pin lodash to a patched version while workspace packages finish upgrades.", "source": "manual", "securityChecked": true, "securityProvider": "osv", "cves": ["CVE-2021-23337"], "cveDetails": [ { "cve": "CVE-2021-23337", "severity": "high", "patchedVersion": "4.17.21" } ], "severity": "high", "vulnerableRange": "<4.17.21", "patchedVersion": "4.17.21", "keep": { "reason": "Keep until each workspace requests lodash 4.17.21 or newer.", "untilVersion": "4.17.21" } } } } }}The appendix shows why the override was added, why it is needed, or if it can be removed.
overrides, pnpm pnpm.overrides, and Yarn
resolutions--remove-unusedpatch-package files to the overrides they supportworkspaces, depPaths, overridePaths, and
resolutionPaths--dry-run, --quiet, --summary, and
--outputFormat json| Area | Details |
|---|---|
| Package managers | npm, pnpm, Yarn, Bun |
| Runtime | Node 20.19+ |
| Security default | OSV, no token required |
| Optional providers | GitHub, npm audit, Snyk, Socket, Spektion |
| Monorepos | Auto-detects workspaces; accepts explicit package globs |
| CI | CLI flags plus a GitHub Action |
| Test surface | 2,000+ test cases across unit, integration, and e2e fixtures |
Use Pastoralist to document dependency overrides, remove the ones you no longer need, and track override security fixes.
It is designed to sit beside tools such as npm audit, Dependabot, Renovate, patch-package, syncpack, and depcheck. Those tools find or apply dependency changes. Pastoralist keeps the resulting overrides from becoming invisible technical debt.
npm install pastoralist --save-devnpx pastoralist initThen add it to postinstall:
{ "scripts": { "postinstall": "pastoralist" }}Continue with the setup guide, or try a sandbox:
{
"overrides": {
"lodash": "4.17.21"
}
}{
"overrides": {
"lodash": "4.17.21"
},
"pastoralist": {
"appendix": {
"[email protected]": {
"dependents": {
"web-app": "lodash@^4.17.20",
"admin-ui": "lodash@^4.17.19"
},
"ledger": {
"addedDate": "2026-05-06T00:00:00.000Z",
"reason": "Pin lodash to a patched version while workspace packages finish upgrades.",
"source": "manual",
"securityChecked": true,
"securityProvider": "osv",
"cves": ["CVE-2021-23337"],
"cveDetails": [
{
"cve": "CVE-2021-23337",
"severity": "high",
"patchedVersion": "4.17.21"
}
],
"severity": "high",
"vulnerableRange": "<4.17.21",
"patchedVersion": "4.17.21",
"keep": {
"reason": "Keep until each workspace requests lodash 4.17.21 or newer.",
"untilVersion": "4.17.21"
}
}
}
}
}
}npm install pastoralist --save-dev
npx pastoralist init{
"scripts": {
"postinstall": "pastoralist"
}
}