GUIDES · DEPENDENCIES AND BUILD CONFIGURATION
ERR_PNPM_OUTDATED_LOCKFILE on Vercel: regenerate the lockfile the right way
Vercel refuses to install because pnpm-lock.yaml is not up to date with package.json. Why frozen installs fail, how to regenerate the lockfile with the right pnpm version, and what not to do.
The error
ERR_PNPM_OUTDATED_LOCKFILE Cannot install with frozen-lockfile because pnpm-lock.yaml is not up to date with package.json. Vercel installs with a frozen lockfile so builds are reproducible. Any drift between the two files stops the install.
The usual causes
A dependency was added or bumped in package.json without running pnpm install. The lockfile was written by a different major pnpm version than the one Vercel uses. A dependency is pinned to latest or a range the lockfile cannot satisfy.
Regenerate it
Pin the package manager in package.json so Vercel and your machine agree, delete the stale lockfile, install, and commit the result.
corepack use pnpm@10
rm pnpm-lock.yaml
pnpm install
git add package.json pnpm-lock.yaml
git commit -m "Regenerate lockfile with pnpm 10"What not to do
Adding --no-frozen-lockfile to the install command makes the error go away and hides the drift. Builds stop being reproducible and the next contributor gets a different tree. Fix the lockfile instead. The same applies to npm ci and yarn install --immutable.
Updated 2026-10-05