Current section
Files
Jump to
Current section
Files
README.md
# NPM[](https://hex.pm/packages/npm)[](https://github.com/elixir-volt/npm_ex/actions/workflows/ci.yml)npm package manager for Elixir — no Node.js required.Resolve, fetch, cache, and link npm packages directly from Mix.## Installation```elixirdef deps do [{:npm, "~> 0.4.0"}]end```## Usage```sh# Initialize a new package.jsonmix npm.init# Install all deps from package.jsonmix npm.install# Add a package (latest)mix npm.install lodash# Add with version rangemix npm.install lodash@^4.0# Scoped packagesmix npm.install @types/node@^20# Add as dev dependencymix npm.install eslint --save-dev# Pin exact version (no ^ prefix)mix npm.install lodash --save-exact# Production install (skip devDependencies)mix npm.install --production# Remove a packagemix npm.remove lodash# Update packagesmix npm.update # Update allmix npm.update lodash # Update specific# List installed packagesmix npm.list# Show dependency treemix npm.tree# Show outdated packagesmix npm.outdated# Explain why a package is installedmix npm.why accepts# Show package info from the registrymix npm.info express# Search the registrymix npm.search react# Run a script from package.jsonmix npm.run build# Execute a binary from node_modules/.binmix npm.exec eslint .# Fetch locked deps without re-resolvingmix npm.get# CI mode — fail if lockfile is stalemix npm.install --frozenmix npm.ci# Verify installation statemix npm.check# Clean node_modulesmix npm.clean# Cache managementmix npm.cache statusmix npm.cache clean# Show configurationmix npm.config```## How it works1. Reads dependencies from `package.json` (supports `dependencies`, `devDependencies`, `overrides`)2. Resolves the full dependency tree using [PubGrub](https://hex.pm/packages/hex_solver) with [npm semver](https://hex.pm/packages/npm_semver)3. Downloads tarballs from the npm registry with SHA-512/SHA-256/SHA-1 integrity verification4. Caches packages globally in `~/.npm_ex/cache/` — download once, reuse across projects5. Links into `node_modules/` via symlinks (macOS/Linux) or copies (Windows)6. Creates `node_modules/.bin/` with executable symlinks from package `bin` fields7. Prunes stale packages from `node_modules/` on re-install8. Locks versions in `npm.lock` for reproducible installs9. Warns about unmet peer dependencies and deprecated packages10. Retries failed downloads with exponential backoff## Why `npm.lock` instead of `package-lock.json`?`npm_ex` is not npm, so it keeps its own lockfile. `package.json` is the shared manifest; `npm.lock` is the reproducibility file for the `npm_ex` installer.## ConfigurationSet environment variables to customize behavior:- `NPM_REGISTRY` — custom registry URL (default: `https://registry.npmjs.org`)- `NPM_TOKEN` — authentication token for private registries- `NPM_EX_CACHE_DIR` — custom cache directory (default: `~/.npm_ex/`)## LicenseMIT © 2026 Danila Poyarkov