Skip to main content

npm

Node Package Manager

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/npm

In short

npm is Node.js's default package manager and the world's largest software registry; it downloads a project's dependencies and tracks their versions.

What is npm?

npm was created by Isaac Z. Schlueter in 2010 and ships with every installation of Node.js. It has two parts: a command-line tool that installs and manages packages, and the npm registry, an online store of millions of open-source JavaScript packages that anyone can publish to. It has been owned by GitHub since 2020.

A project lists its dependencies in a package.json file, together with scripts such as test and build. Running npm install downloads the packages, and the packages they depend on, into a node_modules folder and records the exact versions in package-lock.json, so every developer and server gets the same set. Versions follow semantic versioning, and ranges such as ^4.2.0 allow compatible updates.

npm run executes the scripts from package.json, and npx runs a package's command without installing it globally, for example to create a new project. Alternatives such as pnpm, Yarn and Bun use the same registry and package.json, but install packages differently, often faster or with less disk space.

A common misconception is that npm is only for Node.js on servers. Most frontend tools and libraries, such as React, Vite and TypeScript, are installed through it as well. Because installing a package can run its install scripts and pulls in many indirect dependencies, the registry has also been a target of supply chain attacks, so lockfiles and audits matter.

Key takeaways

  • npm is Node.js's package manager and the largest JavaScript package registry.
  • package.json lists dependencies and scripts; package-lock.json pins exact versions.
  • npm install fills node_modules; npm run executes scripts; npx runs package commands.
  • pnpm, Yarn and Bun are alternatives that use the same registry.
  • Lockfiles and audits help guard against supply chain attacks.

Example

A package.json with scripts and dependenciesjson
{
  "name": "my-app",
  "version": "1.0.0",
  "scripts": {
    "dev": "vite",
    "test": "vitest"
  },
  "dependencies": {
    "react": "^19.0.0"
  },
  "devDependencies": {
    "vite": "^7.0.0",
    "vitest": "^3.0.0"
  }
}

Readers ask

What is the difference between npm and npx?

npm installs and manages packages. npx runs a command from a package, downloading it temporarily if it isn't installed, which is handy for one-off tools such as project generators.

What is package-lock.json?

A file npm writes that records the exact version of every installed package, including indirect ones, so that installs on other machines produce the same result. It should be committed to version control.

What is the difference between npm, Yarn and pnpm?

All three install packages from the same registry using package.json. Yarn and pnpm were created to be faster or more efficient; pnpm, for example, stores each package version once on disk and links it into projects.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings