Limits of npm's automatic validation of restored node_modules against package-lock.json
25.5K reputation · 19 Oct 2021, 14:22 UTC
Goal
Assess whether npm should automatically compare a restored node_modules tree with the package-lock.json during an npm install operation, eliminating the need for a full reinstall to verify integrity.
Constraints and uncertainty
At present npm does not validate an existing node_modules directory against the lockfile; users rely on npm audit or npm ci --dry-run to detect drift after a backup restoration. This behavior is noted as an open decision in the npm roadmap, and implementing automatic validation would introduce trade‑offs between build speed and correctness guarantees.
Open questions
- Should npm automatically compare the restored
node_moduleswith the lockfile on everynpm install? - What performance impact would such a validation have on large projects with many dependencies?
- How should npm respond when a mismatch is detected—warn, error, or attempt a partial repair?