← All posts

How npm and package.json Work – A Quick Guide

npm is the tool that lets you grab code from the internet, and package.json is the list of what you need and how to install it.

🚀 The Simple Version

What is npm?

npm (short for Node Package Manager) is like a grocery store for code. Instead of buying apples, you download reusable JavaScript libraries called packages.

What’s in package.json?

Think of package.json as your shopping list. It lists the packages you want, the exact versions, and the commands you can run. The most common fields are:

  • name – the project’s name
  • version – the project’s current version
  • dependencies – packages needed for the app to run
  • devDependencies – packages needed only while you’re developing
  • scripts – shortcuts for commands like npm start or npm test

How npm Uses the List

When you run npm install, npm reads package.json, downloads the listed packages, and saves them in a node_modules folder. It also creates a package-lock.json file that locks every package to a specific version, so everyone on the team gets the same code.

Why Scripts Matter

Scripts let you automate common tasks. For example, npm start might run node index.js, and npm test could run your test suite. It’s a shortcut so you don’t have to remember long commands.

Getting the Most Out of npm

Use npm update to keep dependencies fresh, but always check the lockfile first. If something breaks, you can roll back to the exact version recorded in package-lock.json.