Node.js & npm basics
Run scripts with Node, use built-in modules, manage packages with npm and write npm scripts.
Node.js runs JavaScript outside the browser — on servers, in command-line tools and in the build tools (Vite, TypeScript, ESLint, Prettier) that every front-end project uses. npm is the package manager that comes with Node and gives you access to millions of open-source packages. Even if you only build front-ends, you'll use both every day.
Installing and checking Node#
Install the current LTS release (Node 24 at the time of writing):
Version managers let you switch Node versions per project — many projects record the version they need in a .nvmrc file. Windows users can use the installer from nodejs.org or fnm.
Running code#
What's different from the browser?#
Built-in modules#
Node ships with modules for files, paths, networking and more. Import them with the node: prefix:
node:fs/promises— read, write, list and delete files.node:path— join and split file paths portably (Windows uses\).node:os,node:process— information about the machine and current process.node:http— build web servers (frameworks like Express or Fastify build on it).node:crypto,node:child_process,node:events,node:stream,node:test…
Process: arguments, environment and exit codes
Keep secrets like API keys in environment variables, not in code. Node 20.6+ can load a .env file directly with node --env-file=.env app.js — and never commit .env to git.
A tiny web server#
Run node server.mjs and open http://localhost:3000/api/courses. Real projects usually use a framework like Express, Fastify or Hono for routing and middleware.
npm and package.json#
Every Node project has a package.json describing it. Create one:
(Add "type": "module" yourself so .js files use import/export.)
Installing packages
Packages go into node_modules/ — never commit that folder (add it to .gitignore). Anyone can recreate it with npm install.
Semantic versioning
Versions look like MAJOR.MINOR.PATCH (e.g. 6.0.1):
- MAJOR — breaking changes
- MINOR — new features, backwards compatible
- PATCH — bug fixes
The lockfile
package-lock.json records the exact version of every package (including dependencies of dependencies). Commit it, so teammates, CI and production all install identical code.
npm scripts#
scripts are named commands, run with npm run <name>:
Scripts can use any installed package's command-line tool without a global install, because npm adds node_modules/.bin to the PATH:
npx: run a package without installing it
Testing with the built-in test runner#
Node has a test runner — no extra packages needed:
(Front-end projects usually use Vitest, which has a similar API and understands Vite configs.)
Package safety#
Every dependency is code you run with full access to your machine:
- Prefer well-maintained, widely used packages; check the repository, download stats and last release.
- Run
npm auditto check for known vulnerabilities. - Watch for typo-squatting (
reqeustinstead ofrequest). - Don't add a package for a one-liner you could write yourself.
Alternatives you'll hear about#
- pnpm and Yarn — alternative package managers (pnpm saves disk space with a shared store).
- Deno and Bun — alternative JavaScript runtimes with built-in TypeScript support and tooling; both can run most npm packages.
Common mistakes#
- Committing
node_modulesor.env. - Installing project tools globally (
npm i -g) instead of as dev dependencies — teammates won't get the same version. - Deleting
package-lock.jsonto "fix" problems. - Mixing
requireandimport— choose ESM with"type": "module". - Using
sudo npm install -gon Linux. Use nvm, which installs to your home directory.
What's next#
Next: TypeScript, which adds static types to JavaScript and catches whole classes of bugs before your code runs.
Check your understanding
Quick quiz
1.What is the difference between
dependenciesanddevDependenciesin package.json?2.Why should you commit
package-lock.json?3.What does the version range
"^2.4.1"allow?
Finished reading?
Mark this lesson complete to track your progress.