Four package managers have shaped a decade of JavaScript tooling. npm is the incumbent that ships with Node, Yarn was Facebook’s protest that became a laboratory, pnpm was the efficiency heretic that turned out to be right, and Bun is the systems-language outsider that wants to replace the whole runtime, not just the installer. This is their history as a timeline — every date below was verified against the npm registry’s publish timestamps and the projects’ own announcement posts — followed by where each tool stands today.
The timeline
2010 — npm: the original
Isaac Schlueter’s npm becomes Node’s package manager and, shortly after, the pattern-setter for an entire industry: a flat-ish node_modules tree, a central registry, semantic versioning discipline. For its first five years it has no serious competition — which shows. npm 2’s deeply nested trees produce the infamous node_modules directories so large that developers joke about them being heavier than Pluto. Its real problem is nondeterminism: two developers running npm install on the same package.json can get different trees.
October 2016 — Yarn: the protest candidate
Facebook, Google, Exponent and Tilde ship Yarn, explicitly because npm was slow and nondeterministic at Facebook’s scale. Three ideas land at once: a lockfile (yarn.lock) for reproducible installs, a parallelized and cached download pipeline, and offline installs. The JavaScript world learns overnight that install speed is a designable property, not a fact of life. npm is forced to respond — most observers consider this the most productive rivalry in JS tooling history.
May 2017 — npm 5: the counterpunch
npm 5 answers Yarn directly: package-lock.json arrives (determinism, finally), installs get dramatically faster, and the cache is rewritten. Suddenly the default choice is good enough again — the classic pattern of an incumbent absorbing its challenger’s best ideas.
June–September 2017 — pnpm 1.0 and Yarn 1.0
pnpm (Zoltan Kochan) reaches 1.0 in June 2017 with the most radical idea of the decade: a single global content-addressable store on each machine, with node_modules built from hard links and symlinks. One copy of each package version per disk, period. Combined with a strict, non-flat node_modules layout that prevents you from importing packages you never declared, pnpm solves disk waste and phantom dependencies in one stroke. Most of the ecosystem ignores it. That was a mistake. Yarn 1.0 (“classic”) follows in September and becomes the workhorse generation that a huge share of the industry runs to this day.
2018 — Yarn Plug’n’Play: the bold experiment
Yarn 1.12 introduces Plug’n’Play, and Yarn 2 “Berry” (January 2020) makes it the default: eliminate node_modules entirely, resolve dependencies from a single .pnp.cjs file backed by a zip archive. Technically brilliant — instant installs, strict dependency graph — and culturally too far ahead. The ecosystem’s tooling wasn’t ready, compatibility friction was constant, and PnP strict mode became the most-discussed misfire in modern JS tooling. Berry survived by softening: PnP became optional, and Yarn 3 (July 2021) re-embraced node_modules linker as a first-class citizen.
April 2021 — pnpm 6: monorepos find their tool
Workspaces mature, filtering (--filter) becomes the best-in-class way to operate on package subsets, and the lockfile (pnpm-lock.yaml) stabilizes. As monorepos sweep the industry (Turborepo, Nx, Rush all standardize on pnpm support), pnpm rides the wave it was born for. Adoption starts compounding.
October 2021 — npm 7 and 8: workspaces at last
npm 7 ships workspaces, automatic peer-dependency installation (a decade’s most-requested issue closed), and the lockfile v2 that carries the full tree. npm 8 follows a year later as a polish release. npm is now “fine” — but Yarn Berry and pnpm are defining the frontier.
2022 — pnpm 7: the year it went mainstream
pnpm 7 unifies config under .npmrc-compatible settings, ships pnpm patch, and default-fies the performance settings people used to hand-tune. Vue, Vite, Prisma, Svelte and countless major repos switch. Vite’s own template now scaffolds pnpm by default — a quiet endorsement with enormous reach.
October 2023 — Bun 1.0: the all-in-one insurgent
Bun 1.0 arrives from Oven, written in Zig with JavaScriptCore at its core. The pitch is not “a faster npm” — it’s “a faster everything”: runtime, bundler, test runner, and package manager, with npm-compatible installs claimed an order of magnitude faster than the incumbents. A global cache with hardlinks, parallel everything, and a single binary. The benchmarks were eye-watering and, as with every Bun claim, slightly controversial — but the install experience genuinely reset expectations.
October 2023 — Yarn 4: the sober maturity release
Weeks after Bun’s splash, Yarn 4 ships as Berry’s first recommended-for-everyone release: hardened defaults, native Git dependency support, improved constraints, and official pnpm-style node_modules support stable. Yarn’s arc completes: from radical experiment to conservative choice. The Yarn team’s commentary on Bun that same month is a fascinating window into the rivalry.
2024 — Bun 1.1 (Windows) and pnpm 9
Bun 1.1 (April 2024) brings full Windows support — the last platform gap that kept it out of many workplaces — plus ~20,000 passing Node compat tests added per release cycle. pnpm 9 (April 2024) refreshes the lockfile format and continues the steady cadence. npm meanwhile climbs to 10 and 11, chasing the leaders’ feature sets: npm 9 modernized internals, npm 11 hardened security defaults.
January 2025 — pnpm 10: security becomes the feature
pnpm 10 makes the industry’s most consequential behavioral change in years: postinstall lifecycle scripts no longer run by default. After 2024’s supply-chain scares, the don’t-trust-install-scripts stance flips from opt-in paranoia to default hygiene — and the whole ecosystem follows within months (npm and Yarn add their own approval mechanisms later that year). pnpm also adds onlyBuiltDependencies allowlists and drops Node 18.
February 2025 — Bun 1.2: the text lockfile and node compatibility push
Bun 1.2 switches from Bun’s binary lockfile to a human-readable bun.lock, ships a Node.js compatibility score above 90% on Bun’s test suite, and adds bun update --interactive. The message: we’re not a toy runtime anymore, we’re your build stack. Through 2025–26 the 1.2.x → 1.3 → 1.4 line keeps landing monthly — Bun 1.3 (October 2025) focused on frontend dev serving, and 1.4 (August 2026) on the test runner and Windows hardening, with 1.3’s bun.install registry cache quietly becoming real infrastructure.
Historical scorecard — who was ahead, when
- 2015–2017: Yarn. Determinism + speed forced npm to modernize.
- 2017–2020: Contested. npm 5–6 closed the gap; pnpm’s architecture was quietly superior but niche; Yarn 2’s PnP gamble stalled Yarn’s momentum.
- 2021–2024: pnpm. The store + strict layout + workspaces combination won the monorepo era; Bun arrived and won the benchmarks war.
- 2023–2026: Bun on raw speed and “one tool for everything”; pnpm on trust, defaults, and ecosystem gravity. npm on ubiquity. Yarn Berry on principled engineering — with a shrinking but loyal base.
Where they stand today (September 2026)
npm 12.1 — the platform default. Ships with Node, owns the registry, and has absorbed nearly every competitor feature (lockfiles, workspaces, script approval). Slower than the rest on cold installs, and the 2025 supply-chain incidents hammered its trust margin, but nothing matches its zero-decision convenience.
Yarn 4.x (Berry) — the engineer’s choice. PnP strict mode is now opt-in rather than default, node_modules linker is fully supported, and constraints/plugins make it the most programmable of the four. Its market share has eroded to pnpm and Bun, but enterprise monorepos that standardized on Berry are stable and well-served.
pnpm 12.x — the default recommendation. The content-addressable store, strict dependency semantics, and script-security defaults that everyone else copied have made it the consensus choice for new projects and the lingua franca of monorepos. Fast, safe, boring in the best way. The 2025 year-in-review documents just how much of the industry now runs on it.
Bun 1.4.x — the accelerant. Install speed remains untouchable, the runtime+bundler+tester integration is genuinely productive, and Node compatibility is no longer the punchline. Still the newest, still the riskiest for conservative shops (Zig-based core, fast-moving release cadence), and still the tool whose releases most embarrass the incumbents’ benchmarks.
The fifteen-year arc in one sentence: Yarn proved installs could be engineered, pnpm proved they could be architected, Bun proved they could be fused into the runtime — and npm proved that shipping with the platform beats all three.