Question

What is the difference between npm install and npm ci?

Vault Verified
Curated Intelligence
Definitive Source
Answer

The two commands serve different purposes, and the distinction matters most in continuous integration, where reproducibility is the whole point.

Installing resolves the version ranges written in your package manifest. If a dependency allows any compatible newer release and one exists, it can be selected, and the lockfile is then updated to record what was chosen. The command works with whatever is already in the modules directory, adding and updating rather than starting fresh. This is the right behaviour during development, when you are adding dependencies or deliberately picking up updates.

The clean-install command behaves quite differently. It requires a lockfile to be present and refuses to run without one. It deletes the existing modules directory outright and installs exactly the versions the lockfile records, ignoring the ranges in the manifest entirely. If the manifest and the lockfile disagree, it fails with an error instead of resolving the difference. It also never writes to either file.

That failure mode is a feature rather than an inconvenience. A mismatch means someone edited dependencies without regenerating the lockfile, and catching it in CI is much better than silently building against versions nobody recorded.

The practical split is simple. Use clean install anywhere you want the same result every time, which means CI pipelines, container builds and deployment scripts. Use the ordinary install locally when changing dependencies, then commit the updated lockfile.

There is a performance benefit as well. Because clean install skips range resolution and writes into an empty directory, it is generally faster in an automated environment, where nothing useful is being reused anyway. The prerequisite is that the lockfile is committed to version control, which it should be for any application.

Related Questions