Publishing to the Registry

npm 2,036 publish uploads the tarball you just inspected. Rehearse it first: --dry-run performs every step except the HTTP PUT, and prints the tag and access level it would use.

A rehearsal of a real publishShell
npm publish --dry-run --tag rc
Output
npm notice package: @webcoding/slugify-lite@1.4.1-rc.0
npm notice filename: webcoding-slugify-lite-1.4.1-rc.0.tgz  total files: 4
npm warn This command requires you to be logged in to https://registry.npmjs.org/ (dry-run)
npm notice Publishing to https://registry.npmjs.org/ with tag rc and public access (dry-run)
+ @webcoding/slugify-lite@1.4.1-rc.0

"public access" comes from publishConfig.access in the manifest. Without it a scoped package defaults to private and the publish fails on a free account — the single most common first-publish error. Its sibling publishConfig.registry (or an .npmrc entry) aims the upload at a private registry instead.

Set version numbers with npm version: it validates the bump, writes package.json and the lockfile, then commits and tags:

Bumping a version and cutting a release candidateShell
npm version minor          # 1.3.0 -> v1.4.0, commit + tag
npm version prerelease --preid=rc   # -> v1.4.1-rc.0

Publishing is close to irreversible: unpublishing is free within 72 hours if nothing on the registry depends on the package, and after that needs under 300 weekly downloads and a single maintainer. The version number is burned either way, so plan for npm deprecate (Dist-Tags and Prereleases) instead.