Package & Toolchain Managers arenaPackage & Toolchain Managers
Package, dependency, and toolchain managers developers use to install, pin, and reproduce software environments, judged on lockfile reproducibility, monorepo workspaces, caching and CI speed, supply-chain security, migration paths, and how well an AI agent can drive installs headlessly.
54 user stories · 324 judged cells · updated 2026-09-16 · Evidence as of 2026-09-16
Leaderboard — every product ranked by evidenceLeaderboard
| 1 | 63/100 | 12/100 | 0/100 | 32/100 | 22/100 | ★ 33.9k▲ 9.2k/yrnpm 9.7k/wk | 15/29 verified | 69/100 integrity | |||
| 2 | 58/100 | untested | 8/100 | untested | 36/100 | ★ 96k▲ 17.7k/yrnpm 2.6M/wk | 18/25 verified | 54/100 integrity | |||
| 3 | 21/100 | untested | 0/100 | 44/100 | 59/100 | ★ 49.6k▲ 4.7k/yr | 16/26 verified · 3 disputed | 0/100 integrity | |||
| 4 | 54/100 | untested | 8/100 | 30/100 | 24/100 | ★ 89.8k▲ 30.4k/yrpypi 28.4M/wk | 18/25 verified | 69/100 integrity | |||
| 5 | 38/100 | untested | 0/100 | untested | 70/100 | ★ 36.5k▲ 3.4k/yrnpm 132.7M/wk | 17/26 verified | 58/100 integrity | |||
| 6 | 26/100 | untested | 10/100 | 48/100 | untested | ★ 17.7k▲ 1.2k/yr | 14/15 verified | 100/100 integrity |
Best by user type — persona-weighted winnersBest by user type
Per persona, the product with the highest persona-weighted coverage over just that persona's stories — not the same ranking as the overall PA Score leaderboard above.
Best for platform-engineer
pnpm
59/100
Runner-up:
Bun (package manager) (44/100)
6 platform-engineer stories scored
Story matrix — every product × every judged storyStory matrix
Agent experience — stories about agent experience in this arenaAgent experience
Headless installs
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Agent experience — stories about agent experience in this arenaHave an agent install and update project dependencies non-interactively, with clear exit codes and errors when something fails | ai-native | partialX 6/10 | partialX 4/10 | partialC 6/10 | partialX 6/10 | partialX 6/10 | partialC 6/10 |
Manifest editing
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Agent experience — stories about agent experience in this arenaAdd, remove, and upgrade dependencies through CLI commands that safely rewrite the manifest and lockfile, so an agent never hand-edits them | ai-native | partialX 5/10 | partialC 3/10 | fullX 7/10 | fullX 8/10 | fullC 7/10 | partialC 5/10 |
Structured output
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Agent experience — stories about agent experience in this arenaGet machine-readable (JSON) output from core commands so an agent can parse results instead of scraping text | ai-native | none 0/10 | none 0/10 | none 0/10 | partialC 4/10 | none 0/10 | partialC 3/10 |
| Agent experience — stories about agent experience in this arenaPoint an agent at a documented, text-based lockfile format it can read and diff | ai-native | partialC 6/10 | none 0/10 | partialC 3/10 | partialT 6/10 | fullC 9/10 | partialC 5/10 |
Agenticness — how well agents can access and operate the productAgenticness
Agent access
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs | ai-native | none 0/10 | none 0/10 | none 0/10 | fullT 8/10 | fullT 9/10 | fullT 7/10 |
| Agenticness — how well agents can access and operate the productRun the product headlessly / in CI for automation | ai-native | fullT 7/10 | partialX 6/10 | fullX 8/10 | fullX 8/10 | partialX 6/10 | fullX 8/10 |
| Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Agenticness — how well agents can access and operate the productConnect an agent via an official MCP server | ai-native | none 0/10 | n/a | n/a | n/a | n/a | n/a |
| Agenticness — how well agents can access and operate the productUse an official CLI | ai-native | partialT 5/10 | fullT 8/10 | fullT 9/10 | fullT 9/10 | fullT 9/10 | fullT 8/10 |
| Agenticness — how well agents can access and operate the productDrive the product through a documented public API | ai-native | partialT 3/10 | none 0/10 | none 0/10 | partialT 5/10 | partialT 5/10 | partialT 6/10 |
| Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Agenticness — how well agents can access and operate the productBuild against official SDKs | ai-native | n/a | n/a | n/a | none 0/10 | n/a | n/a |
| Agenticness — how well agents can access and operate the productSubscribe to events via webhooks | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
Agentic features
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background | ai-native | n/a | n/a | n/a | n/a | n/a | partialC 4/10 |
| Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Agenticness — how well agents can access and operate the productOperate the product with natural-language commands | ai-native | n/a | n/a | n/a | none 0/10 | n/a | none 0/10 |
Api quality
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples | ai-native | n/a | n/a | none 0/10 | none 0/10 | none 0/10 | none 0/10 |
| Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent) | ai-native | none 0/10 | none 0/10 | n/a | partialT 4/10 | partialT 4/10 | none 0/10 |
| Agenticness — how well agents can access and operate the productTest against a sandbox environment without touching production data | ai-native | n/a | partialX 5/10 | n/a | n/a | n/a | n/a |
| Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy | ai-native | n/a | n/a | none 0/10 | none 0/10 | none 0/10 | none 0/10 |
Automation depth — how much of the product can run unattendedAutomation depth
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Automation depth — how much of the product can run unattendedPerform bulk operations across many items at once | ai-native | fullX 8/10 | none 0/10 | fullX 7/10 | partialC 4/10 | partialX 6/10 | partialC 5/10 |
| Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events | ai-native | n/a | n/a | n/a | n/a | n/a | partialC 5/10 |
| Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows | ai-native | n/a | n/a | n/a | n/a | n/a | none 0/10 |
| Automation depth — how much of the product can run unattendedVersion, review, and roll back my automations | ai-native | partialX 3/10 | n/a | n/a | n/a | n/a | partialC 4/10 |
Cross platform — stories about cross platform in this arenaCross platform
Platform parity
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Cross platform — stories about cross platform in this arenaUse the same workflow and config on macOS, Linux, and Windows | developer | fullC 9/10 | none 0/10 | partialX 6/10 | fullX 7/10 | partialX 6/10 | partialX 5/10 |
Ecosystem extensibility — stories about ecosystem extensibility in this arenaEcosystem extensibility
Extensibility
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Ecosystem extensibility — stories about ecosystem extensibility in this arenaExtend the manager through third-party taps, overlays, plugins, or backends | developer | fullX 8/10 | none 0/10 | none 0/10 | none 0/10 | none 0/10 | fullX 8/10 |
Private registries
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Ecosystem extensibility — stories about ecosystem extensibility in this arenaPoint the manager at private registries or mirrors with scoped authentication | platform-engineer | partialX 4/10 | none 0/10 | partialC 4/10 | none 0/10 | none 0/10 | partialC 4/10 |
Install reproducibility — stories about install reproducibility in this arenaInstall reproducibility
Bootstrap
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Install reproducibility — stories about install reproducibility in this arenaBootstrap a fresh clone with one command that installs everything the project declares | developer | fullX 8/10 | fullX 8/10 | fullX 8/10 | fullX 8/10 | fullX 8/10 | fullX 8/10 |
Lockfiles
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Install reproducibility — stories about install reproducibility in this arenaEnforce a frozen/immutable lockfile mode that fails the install when the manifest and lockfile disagree | platform-engineer | none 0/10 | none 0/10 | fullC 9/10 | none 0/10 | fullC 9/10 | none 0/10 |
| Install reproducibility — stories about install reproducibility in this arenaInstall dependencies from a lockfile and get the exact same resolved versions on every machine | developer | disputedD 4/10 | partialX 6/10 | fullX 8/10 | fullC 7/10 | fullX 8/10 | partialC 5/10 |
Migration adoption — stories about migration adoption in this arenaMigration adoption
Compatibility
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Migration adoption — stories about migration adoption in this arenaKeep using familiar commands and interface conventions from the incumbent tool while adopting this manager | switcher | partialX 4/10 | none 0/10 | partialX 7/10 | partialX 7/10 | fullX 8/10 | fullX 8/10 |
Migration
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Migration adoption — stories about migration adoption in this arenaMigrate an existing project from the incumbent tool with documented import or conversion tooling | switcher | none 0/10 | none 0/10 | partialX 6/10 | partialX 6/10 | fullX 7/10 | fullX 8/10 |
Monorepo workspaces — stories about monorepo workspaces in this arenaMonorepo workspaces
Workspaces
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Monorepo workspaces — stories about monorepo workspaces in this arenaManage many packages in one monorepo with workspaces sharing a single lockfile and cross-linked local dependencies | developer | n/a | none 0/10 | fullX 9/10 | fullC 7/10 | fullX 8/10 | n/a |
| Monorepo workspaces — stories about monorepo workspaces in this arenaRun installs and scripts filtered to a subset of workspace packages (including only those affected by a change) | developer | n/a | none 0/10 | fullX 8/10 | none 0/10 | partialX 6/10 | none 0/10 |
Openness — open source, data portability, and self-hosting storiesOpenness
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Openness — open source, data portability, and self-hosting storiesDo everything through the API that I can do in the UI | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave | ai-native | fullC 7/10 | n/a | n/a | partialC 5/10 | n/a | partialC 5/10 |
| Openness — open source, data portability, and self-hosting storiesRead the product's source under an open license | ai-native | partialC 4/10 | none 0/10 | none 0/10 | partialC 5/10 | none 0/10 | partialC 6/10 |
| Openness — open source, data portability, and self-hosting storiesSelf-host the core product | ai-native | partialX 5/10 | fullX 8/10 | n/a | n/a | n/a | n/a |
Performance caching — stories about performance caching in this arenaPerformance caching
Benchmarks
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Performance caching — stories about performance caching in this arenaSee published benchmarks or measured numbers backing the manager's speed claims | developer | none 0/10 | none 0/10 | partialX 6/10 | none 0/10 | partialX 6/10 | none 0/10 |
Binary caching
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Performance caching — stories about performance caching in this arenaInstall prebuilt binary packages from a cache instead of compiling from source | developer | fullC 8/10 | fullX 9/10 | partialX 6/10 | fullX 8/10 | fullX 7/10 | partialX 6/10 |
Ci speed
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Performance caching — stories about performance caching in this arenaMake CI installs fast with a documented cache-restore setup and offline-capable installs | platform-engineer | none 0/10 | partialX 5/10 | fullX 7/10 | partialX 7/10 | partialC 7/10 | partialX 4/10 |
Disk efficiency
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Performance caching — stories about performance caching in this arenaRely on a shared content-addressable store so the same dependency version is stored once on disk across all projects | developer | partialX 4/10 | fullX 8/10 | fullX 9/10 | fullX 8/10 | fullC 9/10 | none 0/10 |
Privacy posture — data-handling and privacy storiesPrivacy posture
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Privacy posture — data-handling and privacy storiesChoose where my data is stored (region/residency) | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models | ai-native | n/a | n/a | n/a | n/a | n/a | n/a |
| Privacy posture — data-handling and privacy storiesControl data retention and deletion | ai-native | partialC 3/10 | n/a | n/a | n/a | n/a | none 0/10 |
| Privacy posture — data-handling and privacy storiesOpt out of telemetry and usage tracking | ai-native | fullC 8/10 | n/a | n/a | none 0/10 | none 0/10 | none 0/10 |
Security supply chain — stories about security supply chain in this arenaSecurity supply chain
Auditing
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Security supply chain — stories about security supply chain in this arenaAudit installed dependencies for known vulnerabilities directly from the CLI | platform-engineer | none 0/10 | none 0/10 | fullC 8/10 | none 0/10 | fullC 8/10 | none 0/10 |
Hardening
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Security supply chain — stories about security supply chain in this arenaTurn on protections against malicious packages, such as blocking lifecycle scripts or enforcing a minimum release age | platform-engineer | partialX 3/10 | none 0/10 | partialX 6/10 | none 0/10 | partialC 6/10 | fullC 8/10 |
Integrity
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Security supply chain — stories about security supply chain in this arenaTrust that fetched packages are verified against checksums, signatures, or attestations before they run | platform-engineer | partialX 3/10 | none 0/10 | partialC 6/10 | none 0/10 | none 0/10 | fullC 8/10 |
Toolchain management — stories about toolchain management in this arenaToolchain management
Environments
| Story | Persona | ||||||
|---|---|---|---|---|---|---|---|
| Toolchain management — stories about toolchain management in this arenaHave the right tool versions and environment variables activate automatically when I enter a project directory | developer | none 0/10 | partialX 3/10 | partialC 4/10 | partialX 5/10 | n/a | fullX 9/10 |
Adjacent arenas — categories often shopped togetherAdjacent arenas
Shopping this category often means shopping these too.