# Update all the Node dependencies to their latest version

> Learn how to update all your npm dependencies in package.json to their latest versions, using npm update for semver ranges and npm-check-updates for big bumps.

Author: [Flavio Copes](https://flaviocopes.com/about/) | Published: 2018-08-07 | Updated: 2020-04-28 | Topics: [Node.js](https://flaviocopes.com/tags/node/) | Canonical: https://flaviocopes.com/update-npm-dependencies/

When you install a package using `npm install <packagename>`, the latest available version of the package is downloaded and put in the `node_modules` folder, and a corresponding entry is added to the `package.json` and `package-lock.json` files that are present in your current folder.

[npm](https://flaviocopes.com/npm/) calculates the dependencies and installs the latest available version of those as well.

Let's say you install [`cowsay`](https://www.npmjs.com/package/cowsay), a cool command line tool that lets you make a cow say _things_.

When you `npm install cowsay`, this entry is added to the `package.json` file:

```json
{
  "dependencies": {
    "cowsay": "^1.3.1"
  }
}
```

and this is an extract of `package-lock.json`, where I removed the nested dependencies for clarity:

```json
{
  "requires": true,
  "lockfileVersion": 1,
  "dependencies": {
    "cowsay": {
      "version": "1.3.1",
      "resolved": "https://registry.npmjs.org/cowsay/-/cowsay-1.3.1.tgz",
      "integrity": "sha512-3PVFe6FePVtPj1HTeLin9v8WyLl+VmM1l1H/5P+BTTDkMAjufp+0F9eLjzRnOHzVAYeIYFF5po5NjRrgefnRMQ==",
      "requires": {
        "get-stdin": "^5.0.1",
        "optimist": "~0.6.1",
        "string-width": "~2.1.1",
        "strip-eof": "^1.0.0"
      }
    }
  }
}
```

Now those 2 files tell us that we installed version `1.3.1` of cowsay, and our rule for updates is `^1.3.1`, which for [the npm versioning rules](https://flaviocopes.com/npm-semantic-versioning/) means that [npm](https://flaviocopes.com/npm/) can update to patch and minor releases: `1.3.2`, `1.4.0` and so on.

But not for major version changes that break compatibility, which means, in this example, `2.0` and higher.

If you're ever unsure what `^` and `~` allow, my free [semver advisor](https://flaviocopes.com/tools/semver-advisor/) explains the ranges.
 
If there is a new minor or patch release and we type `npm update`, the installed version is updated, and the `package-lock.json` file diligently filled with the new version.

`package.json` remains unchanged.

To discover new releases of the packages, you run `npm outdated`.

Here's the list of a few outdated packages in one repository I didn't update for quite a while:

![Terminal output of npm outdated command showing package versions with Current, Wanted, Latest columns for various packages](https://flaviocopes.com/images/update-npm-dependencies/outdated-packages.png)

Some of those updates are major releases. Running `npm update` won't update the version of those. Major releases are never updated in this way because they (by definition) introduce breaking changes, and `npm` want to save you trouble.

To update to a new major version all the packages, install the `npm-check-updates` package globally:

```bash
npm install -g npm-check-updates
```

then run it:

```bash
ncu -u
```

this will upgrade all the version hints in the `package.json` file, to `dependencies` and `devDependencies`, so npm can install the new major version.

You are now ready to run the update:

```bash
npm update
```

If you just downloaded the project without the `node_modules` dependencies and you want to install the shiny new versions first, just run

```bash
npm install
```
