npm/cli: the package manager that ships inside Node.js
the package manager for JavaScript
At a glance
- What is it?
- npm/cli is the source repository for the npm client that comes bundled with Node.js. It is the default way JavaScript dependencies get resolved, fetched and linked, and it is worth understanding what you actually get before you replace it.
- Who is it for?
- Adopt npm/cli if you are running a currently supported Node.js release and want the default package manager with no extra install step, since it ships bundled with node and with most third-party distributions. Do not reach for it as a standalone installer if you need to pin a client version independently of your runtime, because the README's primary distribution path is Node.js itself.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What npm/cli is, and the problem it removes
npm/cli is the client half of the npm ecosystem. The repository holds the command line tool itself: bin/npm-cli.js and bin/npx-cli.js are the two binaries declared in package.json, and the package is named npm at version 12.0.2 on the latest branch. The problem it solves is dependency resolution and installation for JavaScript projects. You declare what you need, it works out the tree, downloads tarballs, and links them into node_modules.
The audience is anyone writing JavaScript or TypeScript who needs third-party code. That includes front-end projects, Node services, build tooling, and CI pipelines. The README is blunt about distribution: npm comes bundled with node and most third-party distributions by default. That single sentence explains most of npm's adoption. You rarely install npm. You install Node.js and npm arrives with it.
The consequence is that npm's release cadence is partly decoupled from the version you have. The repository's own package.json says 12.0.2, the latest release entry in the changelog is v11.19.1 from 2026-08-26, and the Node.js release you are running may carry something older. Checking the installed client version matters more here than with a tool you install yourself.
How the client is put together
The repository layout tells you the architecture without needing a diagram. lib/ holds the implementation, bin/ holds the two entry points, and the work is delegated to scoped packages under @npmcli/. Arborist handles the dependency tree. @npmcli/config handles configuration loading across .npmrc files and environment variables. @npmcli/run-script executes lifecycle scripts. cacache provides the content-addressable cache. bin-links creates the symlinks and shims in node_modules/.bin.
That split is why the repository has workspaces for docs, smoke-tests, mock-globals and mock-registry. The mock-registry workspace exists so the test suite can exercise install behaviour without hitting the real registry. The mock-globals workspace does the same for ambient state. If you are reading the source to debug an install, start in lib/ rather than in the scoped dependencies, because lib/ wires the command surface to those packages.
Two other details are visible from the top level. The bin field maps npm and npx to separate scripts, so npx is a first-class entry point rather than an alias. And the files array in package.json limits what gets published to bin/, lib/, index.js, docs/content/, docs/output/ and man/. The man pages ship with the package, which is why the local documentation search described in the README works offline.
Installing npm/cli and running a first command
The README's recommended path is not to install npm at all. It says npm comes bundled with node and most third-party distributions by default, and points to nodejs.org/en/download for officially supported distributions. If you already have Node.js, you already have npm.
If you do need npm without a full Node.js distribution, the README offers a direct download path using the project's install script. This pipes a remote script into sh, so read it first if your environment requires that.
curl -qL https://www.npmjs.com/install.sh | shFor managing several Node.js or npm versions side by side, the README does not name a specific tool. It links to a GitHub search for node version managers instead, which is a deliberate non-endorsement. Once the client is present, the usage pattern in the README is a single template: npm followed by a subcommand.
npm <command>The README's links section also notes that you can search the documentation locally rather than on the web, using the help-search subcommand with a query.
npm help-search <query>Where the bundled model breaks down
The biggest limitation is the one the README states as a feature. Because npm ships with Node.js, you cannot freely choose your npm version independent of your runtime. Upgrading the client usually means upgrading Node.js, and upgrading Node.js can break other things in your project. Teams that need a specific npm behaviour on an older runtime have to work around the bundling rather than with it.
The second limitation is the default registry. The README says npm is configured to use the npm Public Registry at registry.npmjs.org by default, and that usage is subject to the terms of use at npmjs.com/policies/terms. It also says you can configure any other compatible registry, pointing to the third-party registry documentation. That is a real constraint for air-gapped builds, for organizations with internal mirrors, and for anyone whose builds must not depend on a public endpoint. The README does not describe offline installation, cache seeding, or rollback of a failed install. Those gaps are worth knowing about before you plan a migration.
Finally, npm/cli is the wrong tool if you are not working in JavaScript or Node.js. It resolves package.json and node_modules semantics. Other language ecosystems have their own clients, and npm will not help you there.
Alternatives and how they differ in approach
The README itself points to node version managers as the alternative when you want to manage multiple Node.js or npm versions. That is a different layer of the problem: a version manager controls which runtime and therefore which bundled npm you get, rather than replacing the client.
For replacing the client, the meaningful difference is the installation strategy. npm's documented default is the bundled path plus the npmjs.com install script. An alternative client typically ships as its own package with its own release cadence, so you can pin it independently of Node.js. That is the trade: you gain version independence and lose the zero-install property that makes npm the default everywhere.
The other axis is the registry contract. npm's README frames registry choice as configuration, with registry.npmjs.org as the default and third-party registries supported through documented configuration. Any alternative you evaluate should be checked against the same question: can it read your existing .npmrc, and does it respect the same registry configuration? If it cannot, you are maintaining two sets of credentials and two sets of mirrors.
Maintenance, licence and upgrade cost
The repository is not archived, and the last push was on 2026-09-21. Releases are frequent and granular: v11.19.1 on 2026-08-26, libnpmpack v9.1.13 the same day, and v12.0.2 on 2026-07-29. The release-please configuration files at the top level, release-please-config.json and .release-please-manifest.json, indicate automated release management across the workspace packages, which is why individual scoped packages get their own version entries.
Upgrade cost depends on how you consume it. If npm arrives with your Node.js, upgrades are tied to runtime upgrades and you should read the changelog before moving. If you install directly, you are tracking a client that releases on its own schedule. Either way, the CHANGELOG.md and the release-please manifest are the places to look for breaking changes.
On licensing, the repository's licence field is NOASSERTION, which means GitHub could not match the LICENSE file against a known licence template. The LICENSE file exists at the top level, and .licensee.json is present, so the project does run licence checking. Read the LICENSE file directly rather than assuming a standard identifier. This is a description of what the repository contains, not legal advice.
Editorial conclusion
Adopt npm/cli if you are running a currently supported Node.js release and want the default package manager with no extra install step, since it ships bundled with node and with most third-party distributions. Do not reach for it as a standalone installer if you need to pin a client version independently of your runtime, because the README's primary distribution path is Node.js itself. Before you build anything on it, verify two things: which npm version your Node.js release actually carries, using the version command documented in the README, and whether your package sources are reachable, since the default registry is registry.npmjs.org and the README points elsewhere only through the third-party registry configuration docs.
Frequently asked questions
What is npm CLI?
It is the command line client for the npm package manager, published from the npm/cli repository with the binaries npm and npx. The README describes it as a JavaScript package manager that comes bundled with Node.js and most third-party distributions by default.
How do I install npm CLI?
The README's primary path is to install Node.js, since npm comes bundled with node and most third-party distributions. It also documents a direct download using the custom install.sh script at npmjs.com, run through curl and sh.
How do I install npm CLI on Windows?
The README does not give platform-specific instructions. It points to nodejs.org/en/download for officially supported downloads and distributions, and says npm is bundled with node and most third-party distributions by default.
How do I run npm commands?
The README's usage section gives a single template: npm followed by a subcommand. The links section also mentions searching the documentation locally with the help-search subcommand.
How do I install npm CLI on Linux?
The README does not give Linux-specific steps. It says npm comes bundled with node and most third-party distributions by default, and points to nodejs.org/en/download for officially supported downloads and distributions.
How do I install npm CLI on Ubuntu?
The README does not document a distribution-specific package or command. Its guidance is the same as for other platforms: use a currently supported Node.js release from nodejs.org/en/download, since npm is bundled with node by default.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/npm-cli)