Install an older version of an npm package

By

Learn how to install an older version of an npm package, something that might be useful to solve a compatibility problem

~~~

You can install an old version of an npm package using the @ syntax:

npm install <package>@<version>

Why would you want that? The most common reason: the latest release broke something in your project, and you need to roll back while you figure it out. Or another dependency only works with an older major version.

Example:

npm install cowsay

installs version 1.6.0, the latest release as of September 2026.

Install version 1.2.0 with:

npm install [email protected]

The same can be done with global packages. For example, a legacy project might need Webpack 4:

npm install -g [email protected]

Webpack is on 5.x today, so this stays on the old major on purpose. If you don’t care about the exact patch release, ask for the major only: npm install -g webpack@4 gives you the newest 4.x version.

How do you find the old version numbers?

You might also be interested in listing all the previous versions of a package. You can do it with npm view <package> versions:

❯ npm view cowsay versions

[ '1.0.0',
  '1.0.1',
  '1.0.2',
  '1.0.3',
  '1.1.0',
  ...
  '1.2.0',
  '1.2.1',
  '1.3.0',
  '1.3.1',
  '1.4.0',
  '1.5.0',
  '1.6.0' ]

To see just the latest published version, use the singular form:

npm view cowsay version

Watch out for the caret in package.json

When you install a specific version, npm still saves it in package.json with a caret prefix:

"dependencies": {
  "cowsay": "^1.2.0"
}

The ^ means “this version, or any newer minor or patch release” (see semantic versioning). That’s a problem if you downgraded to dodge a bug: a fresh install without the lockfile can jump right back to the broken version, because it still satisfies the range.

To pin the exact version, add the --save-exact flag, or its -E shorthand:

npm install [email protected] --save-exact

Now package.json contains "cowsay": "1.2.0" and nothing will silently upgrade it.

One more thing. The package-lock.json file records the exact version you installed. As long as you commit it, and your team installs with npm ci, everyone gets the same version even with a caret range. The --save-exact flag is the extra guarantee for when the lockfile gets regenerated.

Tagged: Node.js · All topics

Want me to talk about your product? You can sponsor this site.

~~~

Related posts about node: