Before a package goes anywhere, look at the tarball. npm 2,036 pack --dry-run runs the whole packing pipeline — lifecycle scripts included — and lists the files without writing one:
npm pack --dry-run> @webcoding/slugify-lite@1.3.0 prepack > npm run build > node scripts/build.js npm notice package: @webcoding/slugify-lite@1.3.0 npm notice Tarball Contents npm notice 26B README.md npm notice 52B dist/index.d.ts npm notice 162B dist/index.js npm notice 708B package.json npm notice filename: webcoding-slugify-lite-1.3.0.tgz npm notice package size: 672 B unpacked size: 948 B total files: 4
Four files, no src/, no scripts/, no lockfile — because files listed only dist and README.md. package.json, the readme, the license and the changelog are added back automatically whatever you write.
The prepack line is the other half. npm runs prepack before creating the tarball on both npm pack and npm publish, so wiring your build there makes a stale dist/ impossible to publish. prepublishOnly runs earlier still, but only for npm publish — the right hook for slow release checks.
| Script | npm pack | npm publish | npm install (local) |
|---|---|---|---|
| prepublishOnly | No | Yes | No |
| prepack | Yes | Yes | No |
| prepare | Yes | Yes | Yes |
prepare also runs after npm install in a plain checkout, which is how a package installed from a Git 1,932 URL still gets built — at the cost of running for every contributor, so keep it cheap.