/usr/local/lib/node_modules/npm/docs/output/commands
NameSizeModeActions
npm-access.html84030644editdlrm
npm-adduser.html74460644editdlrm
npm-audit.html261680644editdlrm
npm-bugs.html87820644editdlrm
npm-cache.html93000644editdlrm
npm-ci.html178730644editdlrm
npm-completion.html56650644editdlrm
npm-config.html105610644editdlrm
npm-dedupe.html174840644editdlrm
npm-deprecate.html75800644editdlrm
npm-diff.html155510644editdlrm
npm-dist-tag.html114390644editdlrm
npm-docs.html87240644editdlrm
npm-doctor.html112160644editdlrm
npm-edit.html60520644editdlrm
npm-exec.html195910644editdlrm
npm-explain.html81260644editdlrm
npm-explore.html59570644editdlrm
npm-find-dupes.html140700644editdlrm
npm-fund.html90600644editdlrm
npm-get.html52370644editdlrm
npm-help-search.html56300644editdlrm
npm-help.html59580644editdlrm
npm-init.html187530644editdlrm
npm-install-ci-test.html157760644editdlrm
npm-install-test.html210390644editdlrm
npm-install.html432580644editdlrm
npm-link.html214200644editdlrm
npm-ll.html127840644editdlrm
npm-login.html78650644editdlrm
npm-logout.html68540644editdlrm
npm-ls.html146730644editdlrm
npm-org.html74890644editdlrm
npm-outdated.html138000644editdlrm
npm-owner.html86200644editdlrm
npm-pack.html99200644editdlrm
npm-ping.html57050644editdlrm
npm-pkg.html142800644editdlrm
npm-prefix.html63430644editdlrm
npm-profile.html87680644editdlrm
npm-prune.html124280644editdlrm
npm-publish.html155420644editdlrm
npm-query.html128210644editdlrm
npm-rebuild.html114040644editdlrm
npm-repo.html84040644editdlrm
npm-restart.html67750644editdlrm
npm-root.html60860644editdlrm
npm-run.html147050644editdlrm
npm-sbom.html138630644editdlrm
npm-search.html99380644editdlrm
npm-set.html65340644editdlrm
npm-shrinkwrap.html57030644editdlrm
npm-star.html71720644editdlrm
npm-stars.html56680644editdlrm
npm-start.html70370644editdlrm
npm-stop.html66110644editdlrm
npm-team.html100260644editdlrm
npm-test.html64910644editdlrm
npm-token.html120050644editdlrm
npm-trust.html190330644editdlrm
npm-undeprecate.html65810644editdlrm
npm-uninstall.html108500644editdlrm
npm-unpublish.html103580644editdlrm
npm-unstar.html70250644editdlrm
npm-update.html230560644editdlrm
npm-version.html155800644editdlrm
npm-view.html144980644editdlrm
npm-whoami.html57000644editdlrm
npm.html120700644editdlrm
npx.html124250644editdlrm
Edit: /usr/local/lib/node_modules/npm/docs/output/commands/npm-publish.html (15542B)
npm-publish

npm-publish @11.12.0

Publish a package

Table of contents

Synopsis

npm publish <package-spec>

Description

Publishes a package to the registry so that it can be installed by name.

Examples

Publish the package in the current directory:

npm publish

Publish a specific workspace:

npm publish --workspace=<workspace-name>

Publish multiple workspaces:

npm publish --workspace=workspace-a --workspace=workspace-b

Publish all workspaces:

npm publish --workspaces

By default npm will publish to the public registry. This can be overridden by specifying a different default registry or using a scope in the name, combined with a scope-configured registry (see package.json).

A package is interpreted the same way as other commands (like npm install) and can be:

  • a) a folder containing a program described by a package.json file
  • b) a gzipped tarball containing (a)
  • c) a url that resolves to (b)
  • d) a <name>@<version> that is published on the registry (see registry) with (c)
  • e) a <name>@<tag> (see npm dist-tag) that points to (d)
  • f) a <name> that has a "latest" tag satisfying (e)
  • g) a <git remote url> that resolves to (a)

The publish will fail if the package name and version combination already exists in the specified registry.

Once a package is published with a given name and version, that specific name and version combination can never be used again, even if it is removed with npm unpublish.

As of npm@5, both a sha1sum and an integrity field with a sha512sum of the tarball will be submitted to the registry during publication. Subsequent installs will use the strongest supported algorithm to verify downloads.

Similar to --dry-run see npm pack, which figures out the files to be included and packs them into a tarball to be uploaded to the registry.

Files included in package

To see what will be included in your package, run npm pack --dry-run. All files are included by default, with the following exceptions:

  • Certain files that are relevant to package installation and distribution are always included. For example, package.json, README.md, LICENSE, and so on.

  • If there is a "files" list in package.json, then only the files specified will be included. (If directories are specified, then they will be walked recursively and their contents included, subject to the same ignore rules.)

  • If there is a .gitignore or .npmignore file, then ignored files in that and all child directories will be excluded from the package. If both files exist, then the .gitignore is ignored, and only the .npmignore is used.

    .npmignore files follow the same pattern rules as .gitignore files

  • If the file matches certain patterns, then it will never be included, unless explicitly added to the "files" list in package.json, or un-ignored with a ! rule in a .npmignore or .gitignore file.

  • Symbolic links are never included in npm packages.

See developers for full details on what's included in the published package, as well as details on how the package is built.

See package.json for more info on what can and can't be ignored.

Configuration

tag

  • Default: "latest"
  • Type: String

If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag.

It is the tag added to the package@version specified in the npm dist-tag add command, if no explicit tag is given.

When used by the npm diff command, this is the tag used to fetch the tarball that will be compared with the local files by default.

If used in the npm publish command, this is the tag that will be added to the package submitted to the registry.

access

  • Default: 'public' for new packages, existing packages it will not change the current level
  • Type: null, "restricted", or "public"

If you do not want your scoped package to be publicly viewable (and installable) set --access=restricted.

Unscoped packages cannot be set to restricted.

Note: This defaults to not changing the current access level for existing packages. Specifying a value of restricted or public during publish will change the access for an existing package the same way that npm access set status would.

dry-run

  • Default: false
  • Type: Boolean

Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, install, update, dedupe, uninstall, as well as pack and publish.

Note: This is NOT honored by other network related commands, eg dist-tags, owner, etc.

otp

  • Default: null
  • Type: null or String

This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with npm access.

If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one.

workspace

  • Default:
  • Type: String (can be set multiple times)

Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option.

Valid values for the workspace config are either:

  • Workspace names
  • Path to a workspace directory
  • Path to a parent workspace directory (will result in selecting all workspaces within that folder)

When set for the npm init command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project.

This value is not exported to the environment for child processes.

workspaces

  • Default: null
  • Type: null or Boolean

Set to true to run the command in the context of all configured workspaces.

Explicitly setting this to false will cause commands like install to ignore workspaces altogether. When not set explicitly:

  • Commands that operate on the node_modules tree (install, update, etc.) will link workspaces into the node_modules folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, unless one or more workspaces are specified in the workspace config.

This value is not exported to the environment for child processes.

include-workspace-root

  • Default: false
  • Type: Boolean

Include the workspace root when workspaces are enabled for a command.

When false, specifying individual workspaces via the workspace config, or all workspaces via the workspaces flag, will cause npm to operate only on the specified workspaces, and not on the root project.

This value is not exported to the environment for child processes.

provenance

  • Default: false
  • Type: Boolean

When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from.

This config cannot be used with: provenance-file

provenance-file

  • Default: null
  • Type: Path

When publishing, the provenance bundle at the given path will be used.

This config cannot be used with: provenance

See Also