# What Are the Dependencies for the Corsair Project? Complete Dependency Guide for the Monorepo

> Uncover the Corsair project dependencies. Understand root-level development tooling and per-plugin runtime needs, featuring common peer dependencies like corsair and zod. Your complete guide.

- Repository: [corsairdev/corsair](https://github.com/corsairdev/corsair)
- Tags: tutorial
- Published: 2026-09-01

---

**The Corsair project dependencies are split between root-level development tooling and per-plugin runtime dependencies, with `corsair` and `zod` as common peer dependencies across all plugins.**

Understanding what are the dependencies for the Corsair project requires examining its workspace-style TypeScript architecture. The `corsairdev/corsair` repository organizes code as a pnpm monorepo where the root [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json) contains only build and test tooling, while each plugin maintains its own targeted dependency list. This design keeps bundles minimal and prevents version conflicts across the ecosystem.

## Root-Level Dependencies: Build and Tooling Only

The root [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json) in [corsairdev/corsair](https://github.com/corsairdev/corsair) defines strictly **development-time dependencies**. No runtime code ships from this level.

### Core Tooling Packages

| Package | Version | Purpose |
|---------|---------|---------|
| `@biomejs/biome` | 2.3.5 | Linting and formatting |
| `@total-typescript/ts-reset` | ^0.5.1 | TypeScript type improvements |
| `@types/bun`, `@types/node` | latest | Runtime type definitions |
| `bumpp` | ^10.3.1 | Version bumping utility |
| `lint-staged` | ^10.3.1 | Pre-commit linting |
| `simple-git-hooks` | ^2.13.1 | Git hook management |
| `tinyglobby` | ^0.2.15 | Fast glob matching |
| `tsx` | ^4.20.6 | TypeScript execution |
| `turbo` | ^2.6.1 | Monorepo task runner |
| `typescript` | (catalog) | Shared compiler version |
| `yaml` | ^2.8.1 | YAML parsing utilities |

Source: [[`/blob/main/package.json`](https://github.com/corsairdev/corsair/blob/main//blob/main/package.json)](/blob/main/package.json)

To install these root dependencies:

```bash
pnpm install

```

## Plugin-Level Dependencies: Where Runtime Code Lives

Each plugin in `packages/` contains its own [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json) with **peer dependencies**, **runtime dependencies**, and **dev dependencies**. This is where you find the actual functionality dependencies.

### Common Peer Dependencies in Every Plugin

Two packages appear universally as peer dependencies:

- **`corsair`** (`workspace:*`) — the core library, linked via pnpm workspace protocol
- **`zod`** (^4.x) — schema validation library used across the entire framework

Example from [[`packages/zoom/package.json`](https://github.com/corsairdev/corsair/blob/main/packages/zoom/package.json)](/blob/main/packages/zoom/package.json):

```json
{
  "peerDependencies": {
    "corsair": "workspace:*",
    "zod": "^4.0.0"
  }
}

```

### Plugin-Specific Runtime Dependencies

Individual plugins add only what they need. Common patterns include:

- **Slack plugin**: `@slack/web-api`
- **Gmail plugin**: `googleapis`
- **Generic HTTP plugins**: `axios`
- **Utility plugins**: `lodash`, `dayjs`

The Zoom plugin demonstrates minimal runtime dependencies—it declares **only peer dependencies**, staying lightweight. Source: [[`packages/zoom/package.json`](https://github.com/corsairdev/corsair/blob/main/packages/zoom/package.json)](/blob/main/packages/zoom/package.json)

### Dev Dependencies Inside Plugins

Plugin development requires additional tooling:

- **`tsup`** — fast bundler for TypeScript libraries
- **`jest`, `ts-jest`** — testing framework
- **`typescript`** (catalog reference) — type checking
- **`zod`** — often duplicated as dev dependency for type safety

## How the Dependency Hierarchy Works

### 1. Root Defines Tooling, Not Runtime

The root [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json) contains **zero runtime dependencies**. Published packages rely exclusively on dependencies declared in each plugin's own [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json).

### 2. Workspace Linkage via pnpm

The `workspace:*` protocol in [[`pnpm-workspace.yaml`](https://github.com/corsairdev/corsair/blob/main/pnpm-workspace.yaml)](/blob/main/pnpm-workspace.yaml) makes the core `corsair` library available to every plugin without duplicating the package.

### 3. Peer Dependencies Ensure Consistency

Most plugins list `corsair` and `zod` as **peer dependencies**, guaranteeing:
- Single version of core library across all plugins
- Schema validator consistency
- Smaller bundle sizes

### 4. Plugin-Specific Dependencies Stay Isolated

Each plugin installs only its required SDKs. The Slack plugin never bundles Gmail dependencies, and vice versa.

## Installing and Managing Dependencies

### Full Monorepo Setup

```bash

# Clone and install all dependencies (root + every plugin)

git clone https://github.com/corsairdev/corsair.git
cd corsair
pnpm install

```

### Build All Plugins

```bash
pnpm run build

```

Turbo reads the pipeline configuration and builds packages in dependency order.

### Test Single Plugin

```bash
pnpm --filter @corsair-dev/zoom test

```

### Install Specific Plugin (Consumer Perspective)

```bash

# Adds plugin + its peer dependencies (corsair, zod)

pnpm add @corsair-dev/zoom

```

## Key Files for Dependency Analysis

| File | Role |
|------|------|
| [[`/blob/main/package.json`](https://github.com/corsairdev/corsair/blob/main//blob/main/package.json)](/blob/main/package.json) | Root tooling and workspace configuration |
| [[`/blob/main/packages/zoom/package.json`](https://github.com/corsairdev/corsair/blob/main//blob/main/packages/zoom/package.json)](/blob/main/packages/zoom/package.json) | Typical plugin dependency structure |
| [[`/blob/main/packages/corsair/package.json`](https://github.com/corsairdev/corsair/blob/main//blob/main/packages/corsair/package.json)](/blob/main/packages/corsair/package.json) | Core library that plugins consume |
| [[`/blob/main/pnpm-workspace.yaml`](https://github.com/corsairdev/corsair/blob/main//blob/main/pnpm-workspace.yaml)](/blob/main/pnpm-workspace.yaml) | Workspace glob patterns and settings |

## Summary

- **Root dependencies** are development-only: Biome, Turbo, TypeScript tooling
- **Plugin dependencies** contain all runtime code, managed per-package
- **Peer dependencies** (`corsair`, `zod`) ensure consistency across the monorepo
- **Workspace protocol** (`workspace:*`) links the core library without publishing duplicates
- **Plugin-specific SDKs** (Slack, Gmail, Zoom APIs) stay isolated to their respective packages

## Frequently Asked Questions

### Where are the runtime dependencies defined in Corsair?

Runtime dependencies live in each plugin's [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json) files under `packages/`. The root [`package.json`](https://github.com/corsairdev/corsair/blob/main/package.json) contains only build and development tooling. For example, the Zoom plugin's dependencies are defined in [[`packages/zoom/package.json`](https://github.com/corsairdev/corsair/blob/main/packages/zoom/package.json)](/blob/main/packages/zoom/package.json).

### What is the `workspace:*` protocol used in Corsair dependencies?

The `workspace:*` protocol is a pnpm feature that links packages within the same monorepo. In Corsair, plugins reference the core `corsair` library with `"corsair": "workspace:*"`, ensuring they always use the local version during development and get proper versioning after publish.

### Why does every Corsair plugin list `zod` as a peer dependency?

`zod` provides schema validation for plugin configurations, actions, and triggers. Declaring it as a peer dependency rather than a direct dependency prevents version mismatches and ensures the host application controls the schema validation version used across all plugins.

### How do I install dependencies for just one Corsair plugin?

Navigate to the plugin directory and run `pnpm install`, or use pnpm's filter syntax: `pnpm --filter @corsair-dev/zoom install`. For consuming a published plugin, run `pnpm add @corsair-dev/zoom` which automatically installs the plugin plus its peer dependencies (`corsair` and `zod`).