npm and Managing Packages
npm and Managing Packages
npm stands for Node Package Manager. It is the world's largest software registry and the default package manager that ships with Node.js. With npm you can install, share, and manage reusable code libraries called packages (also called modules or dependencies).
When you install Node.js, npm is installed automatically. Packages published to the npm registry can be installed with a single command and used in your project immediately.
Initialising a Project with package.json
Every Node.js project starts with a package.json file. This file tracks your project's name, version, scripts, and dependencies.
# Create a new project directory and initialise it
mkdir my-api
cd my-api
npm init -y
The -y flag accepts all defaults. Here is what the generated package.json looks like:
{
"name": "my-api",
"version": "1.0.0",
"description": "",
"main": "index.js",
"scripts": {
"start": "node index.js",
"dev": "nodemon index.js"
},
"keywords": [],
"author": "Amara Okafor",
"license": "ISC"
}
Installing Packages
# Install a package as a production dependency
npm install express
# Install a package as a development dependency (only needed during development)
npm install --save-dev nodemon
# Install a specific version
npm install express@4.18.2
# Install globally (available from anywhere on your machine)
npm install -g nodemon
After installing Express, your package.json is updated:
{
"dependencies": {
"express": "^4.18.2"
},
"devDependencies": {
"nodemon": "^3.0.1"
}
}
node_modules and package-lock.json
When you install a package, npm creates two things:
-
node_modules/ — a folder containing the installed packages and all their dependencies. This folder can be very large and should never be committed to Git. Add it to
.gitignore. -
package-lock.json — a file that records the exact version of every package installed, including nested dependencies. Always commit this file — it ensures every developer on your team installs the exact same versions.
# Create a .gitignore file
echo "node_modules/" > .gitignore
# When cloning a project, install all dependencies listed in package.json
npm install
npm Scripts
The scripts field in package.json lets you define shortcut commands:
{
"scripts": {
"start": "node index.js",
"dev": "nodemon index.js",
"test": "jest",
"build": "tsc"
}
}
npm start # runs: node index.js
npm run dev # runs: nodemon index.js
npm test # runs: jest
Useful npm Commands
npm list # List all installed packages
npm list --depth=0 # List only top-level packages
npm outdated # Show packages with newer versions available
npm update # Update all packages to latest compatible versions
npm uninstall express # Remove a package
npm audit # Scan for security vulnerabilities
npm audit fix # Automatically fix vulnerabilities
Semantic Versioning (SemVer)
Package versions follow the format MAJOR.MINOR.PATCH (e.g., 4.18.2).
| Part | Meaning | Example |
|---|---|---|
| MAJOR | Breaking changes — your code may break | 4.x.x to 5.x.x |
| MINOR | New features, backwards compatible | 4.17.x to 4.18.x |
| PATCH | Bug fixes, backwards compatible | 4.18.1 to 4.18.2 |
The ^ prefix (caret) in "express": "^4.18.2" means "install the latest version compatible with 4.x.x but not 5.0.0".
Key Takeaways
- npm is Node.js's built-in package manager and the world's largest JavaScript registry.
- Initialise every project with
npm initto create apackage.jsonthat tracks your dependencies. - Production dependencies go in
dependencies; development-only tools go indevDependencies. - Never commit
node_modules/to Git. Always commitpackage-lock.json. - Semantic versioning (SemVer) communicates whether a new version has breaking changes, new features, or bug fixes.
Practice Exercise
- Create a new directory called
backend-practiceand initialise it withnpm init -y. - Install
expressas a production dependency andnodemonas a dev dependency. - Add a
devscript topackage.jsonthat runsnodemon index.js. - Create an
index.jsthat logs "Server starting..." and run it withnpm run dev. - Run
npm auditand inspect the output.
Try it yourself
Key Takeaways
- npm is the default package manager for Node.js and hosts over two million public packages.
- package.json tracks your project metadata, scripts, and dependencies — always include it in version control.
- node_modules should be in .gitignore; package-lock.json should always be committed.
- Use --save-dev for development tools like nodemon and testing libraries.
- Semantic versioning (MAJOR.MINOR.PATCH) communicates the nature and impact of a version change.
Quick Quiz
1.What does npm stand for?
2.Which file should you NEVER commit to Git in a Node.js project?
3.What does the caret (^) mean in a version string like '"express": "^4.18.2"'?
4.What is the difference between 'dependencies' and 'devDependencies' in package.json?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx