Building a Publishable Package

Before a package goes anywhere, look at the tarball. npm 2,036 pack --dry-run runs the whole packing pipeline — lifecycle scripts included — and lists the files without writing one:

Inspecting the tarball of the library from Section 1.14.1Shell
npm pack --dry-run
Output
> @webcoding/slugify-lite@1.3.0 prepack
> npm run build
> node scripts/build.js
npm notice package: @webcoding/slugify-lite@1.3.0
npm notice Tarball Contents
npm notice 26B  README.md
npm notice 52B  dist/index.d.ts
npm notice 162B dist/index.js
npm notice 708B package.json
npm notice filename: webcoding-slugify-lite-1.3.0.tgz
npm notice package size: 672 B   unpacked size: 948 B   total files: 4

Four files, no src/, no scripts/, no lockfile — because files listed only dist and README.md. package.json, the readme, the license and the changelog are added back automatically whatever you write.

The prepack line is the other half. npm runs prepack before creating the tarball on both npm pack and npm publish, so wiring your build there makes a stale dist/ impossible to publish. prepublishOnly runs earlier still, but only for npm publish — the right hook for slow release checks.

Which lifecycle scripts fire for packing, publishing and a local install
Script npm pack npm publish npm install (local)
prepublishOnly No Yes No
prepack Yes Yes No
prepare Yes Yes Yes

prepare also runs after npm install in a plain checkout, which is how a package installed from a Git 1,932 URL still gets built — at the cost of running for every contributor, so keep it cheap.