Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep package-lock.json committed, leave npm’s package-lock setting enabled, and use npm ci when an install must reproduce the committed dependency tree without changing it. Use npm install for deliberate dependency work, then review the manifest and lockfile changes before committing.

Keep the lockfile enabled and commit it

package-lock.json records the dependency tree npm generated so teammates, deployment environments, and CI can install the same resolved dependencies. Commit it alongside package.json rather than relying on each machine to resolve the manifest’s version ranges independently. See npm’s package-lock.json documentation.

The npm package-lock setting is enabled by default. Avoid setting it to false for routine project work: with that setting, npm ignores package lockfiles during installs and does not write one when saving is enabled. If the project needs to state the default explicitly, put this in its .npmrc:

package-lock=true

Choose the install command for the job

Command or setting Effect Use it when
npm install Uses the lockfile when its resolved versions satisfy the manifest’s ranges; dependency work can update the manifest and lockfile. Setting up a project or intentionally adding or updating dependencies.
npm ci Requires a lockfile, rejects a mismatch between the lockfile and package.json, removes the existing node_modules directory, and does not write either manifest or lockfile. Installing the committed dependency state from scratch in CI, deployment, or a local clean install.

Because npm ci removes node_modules, do not use it when you need to preserve the existing installation directory. npm describes its installs as frozen: npm ci documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make installs consistent across machines

Some npm options change the shape of the dependency tree. If the lockfile was created using options such as legacy-peer-deps or install-links, use the same options when running npm ci. Otherwise, a clean install may not reproduce the tree represented by the lockfile. A committed project-level .npmrc can preserve these settings for developers and CI. The npm ci configuration notes document this requirement.

For example, if the project intentionally created its lockfile with legacy peer-dependency handling, its .npmrc could include:

legacy-peer-deps=true

Align npm versions in local development and CI where practical. npm associates lockfile version 1 with npm 5/6, version 2 with npm 7/8, and version 3 with npm 9 and later. npm can use data from lockfiles made for other generations, but older formats may lack metadata that npm then fetches, and installation can update the lockfile. When changing npm generations, inspect the resulting lockfile diff. See the lockfile format documentation.

Make dependency changes deliberately

  1. Use npm install when you intend to add, update, or otherwise change dependencies. If you want newly added dependencies recorded as exact versions in package.json, use --save-exact.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Review changes to both package.json and package-lock.json. Confirm that the resolved dependency changes are expected before committing them.

  3. Run the project’s normal tests and checks against the updated dependency tree before merging.

npm documents --save-exact and install behavior in its npm install documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Decide how peer-dependency conflicts should behave

By default, npm may resolve certain peer-dependency conflicts and issue a warning. Set strict-peer-deps=true when conflicts should instead stop the install for review. This can prevent a questionable peer resolution from passing unnoticed, but it also means installs fail until the conflict is addressed. The setting is documented for npm ci and npm install.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To apply the choice consistently at project level, add this line to the project’s .npmrc:

strict-peer-deps=true

Treat security fixes as dependency changes

npm audit fix applies remediations using npm install behavior, so it can change the dependency tree. Review its lockfile diff and run the project’s normal verification before accepting the change. If you want to update the lockfile without modifying the current node_modules, use npm audit fix --package-lock-only. See the npm audit documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.