Skip to main content

Package Manager

Pronunciation
PAK-ij MAN-uh-jer
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/package-manager

In short

A package manager is a tool that installs, updates and removes software packages and their dependencies, resolving versions automatically.

What is a package manager?

Modern software is built from many packages, and each of those may depend on others. A package manager reads the list of what a project needs, such as package.json for npm or pyproject.toml for Python, downloads the right versions from a registry such as npmjs.com or PyPI, and works out a set of versions that satisfies everyone's requirements.

There are two broad kinds. Language package managers install libraries into a project: npm, pnpm and Yarn for JavaScript, pip and uv for Python, Cargo for Rust, Maven and Gradle for Java, NuGet for .NET and Composer for PHP. System package managers install programs onto a machine: apt and dnf on Linux, Homebrew on macOS and winget on Windows.

A lockfile, such as package-lock.json or Cargo.lock, records the exact version of every package that was installed, including indirect ones, so every developer and every build gets the same result. Version ranges in the manifest usually follow semantic versioning, which lets compatible bug fixes in while keeping breaking changes out.

A common misconception is that installing a popular package is always safe. Packages run code on your machine, and attackers publish look-alike names or take over abandoned packages in supply-chain attacks. Reviewing new dependencies, committing the lockfile and running audit tools such as npm audit reduce the risk.

Key takeaways

  • A package manager installs packages and resolves their dependencies.
  • It reads a manifest and downloads from a registry such as npm or PyPI.
  • Language managers handle libraries; system managers install programs.
  • Lockfiles pin exact versions so every install is reproducible.
  • Packages can be attack vectors, so review and audit dependencies.

Example

Everyday package manager commandsbash
# JavaScript (npm)
npm install express          # add a dependency and update package.json and the lockfile
npm ci                       # install exactly what the lockfile says (CI)
npm outdated                 # see newer versions

# Python (pip in a virtual environment)
python -m venv .venv && source .venv/bin/activate
pip install requests

# Rust (Cargo)
cargo add serde

# System packages
sudo apt install git         # Debian / Ubuntu
brew install node            # macOS

Readers ask

What is a lockfile?

A file that records the exact versions of all installed packages, including dependencies of dependencies. Committing it means everyone gets an identical install, instead of whatever versions are newest that day.

What is the difference between npm, pnpm and Yarn?

All three install packages from the npm registry using package.json. pnpm saves disk space by sharing one copy of each package across projects, and Yarn and pnpm differ from npm in speed, workspace support and how strictly they arrange the node_modules folder.

What is a package registry?

The server where packages are published and downloaded, such as npmjs.com for JavaScript, PyPI for Python and crates.io for Rust. Companies often run private registries for internal packages.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings