# npm

> a package manager for JavaScript

Latest version **12.0.2** (published 2026-07-29) · Artistic-2.0 license · 0 weekly downloads

## Install

```sh
npm install npm
pnpm add npm
yarn add npm
bun add npm
```

Provides the commands `npm`, `npx`.

## Health

**Score 73/100 (B)** — status: active.

Positive: has types package; esm support; no vulnerabilities; recently updated; high maintenance score; high quality score; popular repo.

Warnings: low downloads; large bundle.

## Facts

| | |
|---|---|
| Version | 12.0.2 |
| Published | 2026-07-29 |
| First published | 2013-07-12 |
| Weekly downloads | 0 |
| License | Artistic-2.0 |
| TypeScript types | separate (@types/npm) |
| Module format | ESM + CommonJS |
| Node | ^22.22.2 \|\| ^24.15.0 \|\| >=26.0.0 |
| Dependencies | 68 |
| Unpacked size | 11.8 MB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 10111 |
| Author | GitHub Inc. |
| Maintainers | saquibkhan, npm-cli-ops, reggi |
| Keywords | install, modules, package manager, package.json |

## Links

- npm: https://www.npmjs.com/package/npm
- Repository: https://github.com/npm/cli
- Homepage: https://docs.npmjs.com/
- Issues: https://github.com/npm/cli/issues
- npm.io page: https://npm.io/package/npm

## Dependencies (68)

- [ms](https://npm.io/package/ms.md) ^2.1.2
- [ini](https://npm.io/package/ini.md) ^7.0.0
- [tar](https://npm.io/package/tar.md) ^7.5.19
- [diff](https://npm.io/package/diff.md) ^8.0.2
- [glob](https://npm.io/package/glob.md) ^13.0.6
- [nopt](https://npm.io/package/nopt.md) ^10.0.1
- [read](https://npm.io/package/read.md) ^6.0.0
- [ssri](https://npm.io/package/ssri.md) ^14.0.0
- [archy](https://npm.io/package/archy.md) ~1.0.0
- [chalk](https://npm.io/package/chalk.md) ^5.6.2
- [p-map](https://npm.io/package/p-map.md) ^7.0.4
- [which](https://npm.io/package/which.md) ^7.0.0
- [abbrev](https://npm.io/package/abbrev.md) ^5.0.0
- [pacote](https://npm.io/package/pacote.md) ^22.0.0
- [semver](https://npm.io/package/semver.md) ^7.8.5
- [cacache](https://npm.io/package/cacache.md) ^21.0.1
- [ci-info](https://npm.io/package/ci-info.md) ^4.4.0
- [is-cidr](https://npm.io/package/is-cidr.md) ^7.0.0
- [minipass](https://npm.io/package/minipass.md) ^7.1.3
- [node-gyp](https://npm.io/package/node-gyp.md) ^13.0.0
- [proc-log](https://npm.io/package/proc-log.md) ^7.0.0
- [bin-links](https://npm.io/package/bin-links.md) ^7.0.0
- [libnpmorg](https://npm.io/package/libnpmorg.md) ^9.0.0
- [minimatch](https://npm.io/package/minimatch.md) ^10.2.5
- [treeverse](https://npm.io/package/treeverse.md) ^3.0.0
- [@npmcli/fs](https://npm.io/package/@npmcli/fs.md) ^6.0.0
- [libnpmdiff](https://npm.io/package/libnpmdiff.md) ^9.0.2
- [libnpmexec](https://npm.io/package/libnpmexec.md) ^11.0.2
- [libnpmfund](https://npm.io/package/libnpmfund.md) ^8.0.2
- [libnpmpack](https://npm.io/package/libnpmpack.md) ^10.0.2
- [libnpmteam](https://npm.io/package/libnpmteam.md) ^9.0.0
- [text-table](https://npm.io/package/text-table.md) ~0.2.0
- [@npmcli/git](https://npm.io/package/@npmcli/git.md) ^8.0.0
- [fs-minipass](https://npm.io/package/fs-minipass.md) ^3.0.3
- [graceful-fs](https://npm.io/package/graceful-fs.md) ^4.2.11
- [npm-profile](https://npm.io/package/npm-profile.md) ^13.0.1
- [libnpmaccess](https://npm.io/package/libnpmaccess.md) ^11.0.0
- [libnpmsearch](https://npm.io/package/libnpmsearch.md) ^10.0.0
- [@sigstore/tuf](https://npm.io/package/@sigstore/tuf.md) ^5.0.0
- [libnpmpublish](https://npm.io/package/libnpmpublish.md) ^12.0.0
- [libnpmversion](https://npm.io/package/libnpmversion.md) ^9.0.0
- [@npmcli/config](https://npm.io/package/@npmcli/config.md) ^11.0.1
- [@npmcli/redact](https://npm.io/package/@npmcli/redact.md) ^5.0.0
- [supports-color](https://npm.io/package/supports-color.md) ^10.2.2
- [hosted-git-info](https://npm.io/package/hosted-git-info.md) ^10.1.1
- [npm-package-arg](https://npm.io/package/npm-package-arg.md) ^14.0.0
- [qrcode-terminal](https://npm.io/package/qrcode-terminal.md) ^0.12.0
- [@npmcli/arborist](https://npm.io/package/@npmcli/arborist.md) ^10.0.2
- [npm-audit-report](https://npm.io/package/npm-audit-report.md) ^8.0.0
- [init-package-json](https://npm.io/package/init-package-json.md) ^9.0.0
- [make-fetch-happen](https://npm.io/package/make-fetch-happen.md) ^16.0.1
- [minipass-pipeline](https://npm.io/package/minipass-pipeline.md) ^1.2.4
- [npm-pick-manifest](https://npm.io/package/npm-pick-manifest.md) ^12.0.0
- [npm-user-validate](https://npm.io/package/npm-user-validate.md) ^5.0.0
- [@npmcli/run-script](https://npm.io/package/@npmcli/run-script.md) ^11.0.0
- [npm-install-checks](https://npm.io/package/npm-install-checks.md) ^9.0.0
- [npm-registry-fetch](https://npm.io/package/npm-registry-fetch.md) ^20.0.1
- [tiny-relative-date](https://npm.io/package/tiny-relative-date.md) ^2.0.2
- [fastest-levenshtein](https://npm.io/package/fastest-levenshtein.md) ^1.0.16
- [parse-conflict-json](https://npm.io/package/parse-conflict-json.md) ^6.0.0
- [@npmcli/package-json](https://npm.io/package/@npmcli/package-json.md) ^8.0.0
- [@npmcli/promise-spawn](https://npm.io/package/@npmcli/promise-spawn.md) ^10.0.0
- [spdx-expression-parse](https://npm.io/package/spdx-expression-parse.md) ^4.0.0
- [@npmcli/map-workspaces](https://npm.io/package/@npmcli/map-workspaces.md) ^6.0.0
- [validate-npm-package-name](https://npm.io/package/validate-npm-package-name.md) ^8.0.0
- [@npmcli/metavuln-calculator](https://npm.io/package/@npmcli/metavuln-calculator.md) ^10.0.0
- [@isaacs/string-locale-compare](https://npm.io/package/@isaacs/string-locale-compare.md) ^1.1.0
- [json-parse-even-better-errors](https://npm.io/package/json-parse-even-better-errors.md) ^6.0.0

## Alternatives

- [@mapbox/jsonlint-lines-primitives](https://npm.io/package/@mapbox/jsonlint-lines-primitives.md) — 5.3M weekly downloads
- [reftools](https://npm.io/package/reftools.md) — 3.5M weekly downloads
- [@hey-api/openapi-ts](https://npm.io/package/@hey-api/openapi-ts.md) — 3.5M weekly downloads
- [@mapbox/geojson-rewind](https://npm.io/package/@mapbox/geojson-rewind.md) — 2.4M weekly downloads
- [turbo-stream](https://npm.io/package/turbo-stream.md) — 1.7M weekly downloads

## Recent versions

- 12.0.2 (latest) — 2026-07-29
- 11.19.1 (next-11) — 2026-08-26
- 10.9.9 (next-10) — 2026-07-29
- 9.9.4 (next-9) — 2024-12-09
- 8.19.4 (next-8) — 2023-02-14
- 6.14.18 (v6.14-next) — 2022-12-21
- 7.24.2 (next-7) — 2021-10-04
- 5.10.0 (latest-5) — 2018-05-11
- 4.6.1 (latest-4) — 2017-04-22
- 2.15.12 (next-2) — 2017-03-27
- 3.10.10 (latest-3) — 2016-11-05
- 1.4.29 (latest-1) — 2015-10-30
- 11.19.0 — 2026-07-29
- 12.0.1 — 2026-07-10
- 12.0.0 — 2026-07-08
- … 590 more at https://npm.io/package/npm/versions

## README

# npm - a JavaScript package manager

### Requirements

You should be running a currently supported version of [Node.js](https://nodejs.org/en/download/) to run **`npm`**.  For a list of which versions of Node.js are currently supported, please see the [Node.js releases](https://nodejs.org/en/about/previous-releases) page.

### Installation

**`npm`** comes bundled with [**`node`**](https://nodejs.org/), & most third-party distributions, by default. Officially supported downloads/distributions can be found at: [nodejs.org/en/download](https://nodejs.org/en/download)

#### Direct Download

You can download & install **`npm`** directly from [**npmjs**.com](https://npmjs.com/) using our custom `install.sh` script:

```bash
curl -qL https://www.npmjs.com/install.sh | sh
```

#### Node Version Managers

If you're looking to manage multiple versions of **`Node.js`** &/or **`npm`**, consider using a [node version manager](https://github.com/search?q=node+version+manager+archived%3Afalse&type=repositories&ref=advsearch)

### Usage

```bash
npm <command>
```

### Links & Resources

* [**Documentation**](https://docs.npmjs.com/) - Official docs & how-tos for all things **npm**
    * Note: you can also search docs locally with `npm help-search <query>`
* [**Bug Tracker**](https://github.com/npm/cli/issues) - Search or submit bugs against the CLI
* [**Community Feedback and Discussions**](https://github.com/orgs/community/discussions/categories/npm) - Contribute ideas & discussion around the npm registry, website & CLI
* [**RFCs**](https://github.com/npm/rfcs) - Contribute ideas & specifications for the API/design of the npm CLI
* [**Service Status**](https://status.npmjs.org/) - Monitor the current status & see incident reports for the website & registry
* [**Project Status**](https://npm.github.io/statusboard/) - See the health of all our maintained OSS projects in one view
* [**Support**](https://www.npmjs.com/support) - Experiencing problems with the **npm** [website](https://npmjs.com) or [registry](https://registry.npmjs.org)? [File a ticket](https://www.npmjs.com/support)

### Acknowledgments

* `npm` is configured to use the **npm Public Registry** at [https://registry.npmjs.org](https://registry.npmjs.org) by default; Usage of this registry is subject to **Terms of Use** available at [https://npmjs.com/policies/terms](https://npmjs.com/policies/terms)
* You can configure `npm` to use any other compatible registry you prefer. You can read more about [configuring third-party registries](https://docs.npmjs.com/cli/v7/using-npm/registry)

### FAQ on Branding

#### Is it "npm" or "NPM" or "Npm"?

**`npm`** should never be capitalized unless it is being displayed in a location that is customarily all-capitals (ex. titles on `man` pages).

#### Is "npm" an acronym for "Node Package Manager"?

Contrary to popular belief, **`npm`** **is not** an acronym for "Node Package Manager." It is a recursive backronymic abbreviation for **"npm is not an acronym"** (if the project were named "ninaa," then it would be an acronym). The precursor to **`npm`** was actually a bash utility named **"pm"**, which was the shortform name of **"pkgmakeinst"** - a bash function that installed various things on various platforms. If **`npm`** were ever considered an acronym, it would be as "node pm" or, potentially, "new pm".

---
_Source: https://npm.io/package/npm · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
