Home·Error messages

npm · npm

The message

npm ERR! The `npm ci` command can only install with an existing package-lock.json or npm-shrinkwrap.json

What it means

npm ci does not run at all without a lockfile, because it has nothing telling it which versions to install. It happens when package-lock.json is in .gitignore, was never committed, or when the directory you are standing in is not the project root. npm install --package-lock-only writes the lockfile without installing anything, and committing it makes CI work. Never put package-lock.json in .gitignore: the guarantee that CI builds the same thing twice rests on that one file.

The fix

npm install --package-lock-only
Printed by
npm
npm
20

With npm the cause sits in the first code XXXX line rather than the last six npm ERR! lines, and when the failure comes from the dependency tree or a native build instead of your own code, deleting node_modules and installing again clears about half of them.

Reading an error message

  • Read from the first line down. The lower you go the more it is about the tool’s internals; the cause is usually at the top.
  • If there is a file and a line number, start there — not the top stack frame, but the topmost line that names a file you wrote.
  • Search the message verbatim, but strip your own paths and variable names first; those are what stop the search from matching.
  • The same condition is worded differently across tool versions. If results look wrong, add the version number to the query.
  • Before pasting a fix, check what it throws away. Some of these cannot be undone.

Common questions

Q. What does “npm ERR! The `npm ci` command can only install with an existing package-lock.json or npm-shrinkwrap.json” mean?

npm ci does not run at all without a lockfile, because it has nothing telling it which versions to install. It happens when package-lock.json is in .gitignore, was never committed, or when the directory you are standing in is not the project root. npm install --package-lock-only writes the lockfile without installing anything, and committing it makes CI work. Never put package-lock.json in .gitignore: the guarantee that CI builds the same thing twice rests on that one file.

Q. How do I fix it?

npm install --package-lock-only — before running it, check the explanation above for what this command discards.

Q. Which tool prints this?

npm. It sits under npm, and the message runs to 15 words.

Errors nearby