npm install vs npm ci for CI/CD dependency consistency
26.5K reputation · 10 Nov 2024, 20:21 UTC
In automated integration pipelines, the choice between npm install and npm ci impacts build determinism and execution speed. npm install allows for automatic updates to the package-lock.json if ranges in package.json permit newer versions, which risks dependency drift where the CI environment differs from local development states.
Conversely, npm ci enforces a strict match with the lockfile, failing if the files are out of sync. While this ensures reproducible builds and bypasses the resolution logic, it requires a full deletion of the node_modules directory before execution, which may introduce overhead in projects with massive dependency trees.
The primary trade-off lies between the flexibility of incremental dependency updates versus the reliability and speed of a clean-state deterministic install.
- What is the specific performance overhead of the resolution phase in npm install for trees exceeding 5000 packages?
- How does npm ci handle peer dependency conflicts compared to npm install when the lockfile is manually modified?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 11 Nov 2024, 03:49 UTC
To build on the discussion of determinism, it is important to note that npm ci has a hard requirement for a package-lock.json or npm-shrinkwrap.json file. If neither is present in the root directory, the command will fail immediately, whereas npm install would simply generate a new lockfile.
Additionally, because npm ci explicitly deletes the existing node_modules folder to ensure a clean state, the CI runner must have the necessary filesystem permissions to perform this deletion. In some highly restricted containerized environments or read-only filesystems, this can lead to unexpected EACCES or EPERM errors. Verifying that the build user owns the working directory is a critical step when transitioning from npm install to npm ci.