Yes—when a package contains both .gitignore and .npmignore, npm uses .npmignore to decide which files to exclude and disregards .gitignore for that purpose. If .npmignore is absent, npm uses .gitignore instead. An empty .npmignore can therefore make files excluded only by Git’s ignore rules eligible for publication.
What happens when both ignore files exist?
.npmignore takes precedence over .gitignore for npm package exclusions. The npm documentation says that if both files exist, npm uses .npmignore; .gitignore supplies the rules only when .npmignore is absent. See npm’s published-package rules and its guide to keeping files out of a package.
| Package setup | Effect on npm packaging |
|---|---|
.gitignore exists; .npmignore is absent |
npm uses .gitignore contents as ignore rules. (npm Docs, Developers — Keeping files out of your Package) |
| Both files exist | npm uses .npmignore and disregards .gitignore for package exclusions. (npm Docs, npm-publish — Files included in package) |
.npmignore exists but is empty |
Patterns in .gitignore no longer exclude files through that file; those files may become eligible for inclusion. (npm Docs, Developers — Keeping files out of your Package) |
package.json contains a files field |
It acts as an inclusion allowlist; paths included through it cannot be excluded by either ignore file. (npm Docs, package.json — files) |
Why an empty .npmignore can change the package
An empty .npmignore is still present, so npm does not fall back to .gitignore. That means files previously kept out of Git by ignore patterns—such as local build output, private configuration, or other workspace files—may be picked up by npm’s packaging rules. The empty file does not mean “inherit all Git ignores.”
npm also looks for ignore files in subdirectories, so the root file is not the only one that can affect package contents. .npmignore uses .gitignore-style patterns, including glob patterns and ! negation. npm automatically excludes some paths and always includes certain files, including package.json, README files, and license files; consult the documentation for the npm CLI version you use for the exact rules.
#1 Best Overall
How the package.json files field interacts with ignore rules
The files field in package.json specifies paths to include in the package. npm’s package.json documentation says files included through this field cannot be excluded by .npmignore or .gitignore. Review the allowlist alongside the ignore files: the ignore-file precedence rule alone does not determine every file in the final archive.
Check the archive before publishing
Use npm pack in the package directory to create a local tarball and inspect the file list before you publish. npm documents this as the local packaging step for determining which files would be uploaded.
Rank #2
- Review the package’s
.npmignore,.gitignore, andpackage.jsonfilesfield together. - From the package directory, run
npm pack. - Inspect the generated tarball’s file list. Confirm that intended package files are present and private or unwanted files are absent.
- Publish only after the archive contents match what you expect.
The tarball is the practical check: ignore files and allowlists can interact, so do not assume that Git’s view of the working tree matches the package npm will upload. npm’s package guidance and publish documentation both describe inspecting package contents before publication.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →

