Blog Speed up npm installs without breaking anything

Speed up npm installs without breaking anything

2 min read

Speed up npm installs without breaking anything
TL;DR In CI, use npm ci for a clean, lockfile-exact install and cache the package store between runs. Locally, keep your lockfile committed, prune dependencies you do not use, and avoid reinstalling from scratch when you do not need to.

Slow installs are a quiet tax. A minute here in CI, thirty seconds there on your machine, several times a day, adds up. The good news is that most of the wait is avoidable with a few safe changes. None of these trade correctness for speed.

In CI, use npm ci

npm install is built for development: it resolves versions and can update your lockfile. In a pipeline you want the opposite, an exact, reproducible install.

npm ci

npm ci installs precisely what the lockfile says, refuses to modify it, and gives you a clean, predictable result. It is usually faster than install and it fails loudly if the lockfile and package.json disagree, which is a bug you want to catch.

Cache the store, not node_modules

The biggest CI win is not re-downloading packages every run. Cache the package manager's cache or store, keyed on your lockfile, so an unchanged lockfile means a warm cache.

Cache the store, not node_modules directly. node_modules can be platform-specific and huge, and restoring a stale one causes subtle breakage. The store plus npm ci gives you speed and correctness together.

Locally, do less work

  • Commit your lockfile. It makes installs deterministic and lets tooling skip re-resolving.
  • Do not delete node_modules out of habit. Reach for a clean reinstall only when you actually suspect a corrupt state, not as a reflex.
  • Prune what you do not use. Dependencies you stopped using still cost install time. Trimming them speeds installs and reduces risk.

The mindset

Fast installs come from doing less redundant work, not from skipping steps that keep you safe. Use the reproducible command in CI, cache the right thing, and keep your dependency list honest. That is most of the win, with none of the "it works on my machine" surprises that come from cutting corners.

FAQ

What is the difference between npm install and npm ci?

npm install resolves and can update the lockfile, which is what you want while developing. npm ci installs exactly what the lockfile specifies, refuses to change it, and wipes node_modules first, which is faster and reproducible, which is what you want in CI.

Should I cache node_modules in CI?

Cache the package manager's store or download cache keyed on the lockfile, rather than node_modules itself. That gives you fast installs without shipping a stale or platform-specific modules folder between runs.

Do too many dependencies slow installs?

Yes. Every dependency and its own dependencies add download and link work. Periodically pruning packages you no longer use makes installs smaller and faster, and shrinks your attack surface too.