Contents

Frontend Development › Frontend Build Tooling

package.json

The manifest of a JavaScript project: its dependencies and scripts.

Also known as: package.json file, npm manifest, Node manifest

package.json is the manifest of a JavaScript or Node.js project: it names the project, lists its dependencies and defines its scripts. It sits in the project root, and package managers read it first.

{
  "name": "my-shop",
  "version": "1.2.0",
  "private": true,
  "type": "module",
  "scripts": {
    "dev": "vite",
    "build": "vite build"
  },
  "dependencies": {
    "react": "^18.3.0"
  },
  "devDependencies": {
    "typescript": "^5.4.0",
    "vitest": "^1.6.0"
  },
  "engines": { "node": ">=20" }
}

The fields you’ll use most

FieldPurpose
name, versionIdentity, needed mainly if you publish it
scriptsNamed commands (npm scripts)
dependenciesPackages needed at runtime
devDependenciesPackages needed only for building and testing (compilers, linters, test runners)
peerDependenciesPackages a library expects its host app to provide (peer dependencies)
type"module" makes .js files ES modules
enginesWhich Node versions are supported
privatetrue prevents accidental publishing

Version ranges

"^18.3.0" means “18.3.0 or any newer compatible 18.x”. "~18.3.0" allows only patch updates. A plain "18.3.0" is exact. Ranges follow semantic versioning. The exact versions actually installed are recorded in the lockfile.

Working with it

npm install axios            # adds to dependencies and updates the lockfile
npm install -D vitest        # adds to devDependencies
npm uninstall axios

Prefer these commands over hand-editing dependencies, so the lockfile stays in sync. It’s plain JSON: no comments and no trailing commas, and a typo breaks it. Commit it to Git, and don’t commit node_modules/ (.gitignore).