npm: installing and managing the dependencies of a JavaScript project

npm is the package manager shipped with Node. It installs dependencies, locks their versions and runs the scripts a project declares in its package.json.
3 min read
Believemy logo

Nobody writes their own form validation, their own HTTP client and their own test runner by hand. You install packages, and something has to fetch them, file them away and find the same version again a month later.

That is npm's job, installed alongside Node.js and present on almost every project.


Definition

npm is the package manager of the JavaScript ecosystem. It reads the package.json file, downloads the requested dependencies from a public registry, drops them into the node_modules folder and records the exact versions obtained in package-lock.json.

JAVASCRIPT
// package.json, after "npm install zod" then "npm install -D vitest"
{
  "scripts": {
    "test": "vitest run"
  },
  "dependencies": {
    "zod": "^3.23.8"
  },
  "devDependencies": {
    "vitest": "^2.0.5"
  }
}

The command edited the file on its own: that is the normal way to add a dependency, rather than typing the line by hand and installing afterwards.


The everyday commands

CommandWhat it does
npm installInstalls everything the project declares
npm install packageAdds a dependency and updates package.json
npm install -D packageFiles it under devDependencies
npm ciReinstalls identically from the lock file
npm run buildRuns the script named build
npm outdatedLists dependencies that have fallen behind
Good to know

While an npm script runs, the node_modules/.bin folder is added to the executable path. That is why "build": "vite build" works without installing Vite across the whole machine.


install or ci, the choice that matters

npm install reconciles the project with its dependencies: it happily moves up a version within the allowed range, and rewrites the lock file along the way. It is the development command.

npm ci does the opposite: it deletes node_modules, reinstalls exactly what the lock describes and refuses to start when the lock and package.json contradict each other. It is the continuous integration and deployment command, the one that makes an install reproducible.


Frequently asked questions

Question

Should packages be installed globally?

Usually not. A local install keeps every project on its own version, so a global update cannot break an older piece of work. Keep the global option for a very small number of tools, and launch the rest through a script or through npx.


Question

What should I do when an install fails?

The reflex that solves most cases is deleting node_modules, then running npm install again. If the error survives that, read the line naming a specific package rather than the whole stack, and check which Node version that package expects.


Question

npm, yarn or pnpm?

All three read the same package.json and the same registry, and a project moves between them without rewriting a line of code. pnpm saves a lot of disk space by sharing packages across projects, yarn led on speed for a long time. npm stays the default choice, since it arrives with Node.

Related terms

Discover our javaScript glossary

Every word of JavaScript explained simply: keywords, built-in objects, methods, errors and concepts. Clear definitions and examples that actually run, to learn and to troubleshoot.

Share this article

Want to help us? Share this article on your networks or even better: on your site, in an article or in your newsletter.