web dev//runtime//Node.js//npm
npm is the package manager of the Node.js ecosystem, a command-line tool plus a public registry that installs other people's code into a project, records exactly which versions were used, and runs the project's scripts. Nearly every JavaScript project, frontend or backend, is set up, built and started through it.
npm is the package manager of the Node.js ecosystem, a command-line tool plus a public registry that installs other people's code into a project, records exactly which versions were used, and runs the project's scripts. Nearly every JavaScript project, frontend or backend, is set up, built and started through it.
A project is described by one file, package.json: its name, its scripts ("build": "vite build", "start": "ng serve") and its dependencies with the version ranges it accepts. npm install reads that file, resolves every package and its own dependencies, and writes them into a node_modules folder, often hundreds of packages for a few direct ones.
package.json says what the project accepts; package-lock.json says what it actually got.
Committing the lockfile is what lets a colleague, a CI runner and the production build install the very same tree.
Dependencies come in two kinds. A runtime dependency (React, Express) ships with the application; a devDependency (TypeScript, a test runner, a bundler) is needed only to build or check it, installed with npm install -D. In npm 5 and later --save is the default, so the flag still seen in old tutorials changes nothing.
The lockfile, package-lock.json, pins every resolved version and its checksum. Without it a range like ^4.2.0 can resolve to a newer minor version next month, and a build that worked can break with no change in the project's own code; npm ci installs strictly from the lockfile, which is what CI should run.
Scripts are shortcuts with the project's tools on the path: npm run build can call ng build or vite build even though neither is installed globally. One-off tools run through npx instead.
A dependency is code someone else can change. Every package in node_modules runs with the project's permissions at install time, which is why lockfiles, audits and few dependencies matter for security as much as for reproducibility.
npm pins packages but not the Node.js version that runs them; that layer belongs to a version manager.