Dependency Resolution

How a Package Manager Resolves Dependencies

BookNest's Dependencies to A Real Install Benchmark ran four managers over one package.json and got four different results on disk. All four do the same three jobs, and the differences come from the third:

  1. Resolve: turn each version range into one exact version, recursively, producing a dependency graph. The lockfile is this graph written down.

  2. Fetch: download each tarball once, verify its integrity hash, and keep it in a cache or store.

  3. Link: make the graph visible to Node.js 2,131 : a hoisted folder tree (npm 2,036 , Bun 73,307 ), a tree of symlinks (pnpm 69,400 ) or a lookup map (Yarn 11,798 's Plug'n'Play).

Subsections