Contents

Engineering Craft › Developer Tooling

Package Manager

A tool for installing and versioning dependencies, like npm, pip or cargo.

Also known as: dependency manager, npm, pip, cargo, yarn, pnpm, maven, gradle

A package manager downloads libraries your project depends on, installs them, and records which versions you use, so you don’t copy code by hand.

EcosystemTools
JavaScriptnpm, Yarn, pnpm
Pythonpip, Poetry, uv
RustCargo
JavaMaven, Gradle
RubyBundler
Gothe built-in go modules
npm install lodash          # add a dependency
npm install                 # install everything listed in package.json
pip install requests

What it does

  • Resolves dependencies: your package needs library A, which needs B at some versions. It picks versions that work together.
  • Installs them into the project (node_modules/, a virtual environment).
  • Records them: in a manifest (package.json, pyproject.toml) and a lockfile.
  • Runs scripts and publishes packages in some ecosystems.

Versions

Most use semantic versioning: MAJOR.MINOR.PATCH, where a major bump may break compatibility. A range such as ^1.4.0 in npm accepts newer compatible releases (1.x, from 1.4.0). That convenience is why lockfiles matter.

Habits

  • Add dependencies deliberately. Each one is code you now rely on, with its own bugs and security history. Check that it’s maintained before adding it.
  • Keep the lockfile committed and install from it in CI.
  • Don’t install globally for project dependencies. Use project-local installs (virtual environments in Python).
  • Update regularly, in small steps, rather than once every two years (dependency hell gets worse with delay).
  • Never run sudo pip install to fix permission errors; fix the environment instead.