Every tool in this book installs, pins or ships software that someone else wrote: Git 1,932 stores your lockfile, a Dockerfile runs npm 2,036 ci and apk add, and a Kubernetes 5,150 pod runs an image made mostly of other people's packages. A package manager decides what those packages are, so DevOps starts there.
JavaScript has four serious package managers in 2026: npm, Yarn 11,798 , pnpm 69,400 and Bun 73,307 . They read the same package.json and use the same registry, yet lay out node_modules differently, write different lockfiles and disagree about whether a dependency may run code during installation. This chapter installs BookNest, the bookshop API that runs through all seven chapters, with each of them and measures the results. It then covers the OS package managers that install Node.js 2,131 itself, other language ecosystems, and supply-chain attacks. npm itself is taught in MERN Stack Development, Packages and Monorepos and Security and the Supply Chain, and is not repeated here.
What you will learn
How Yarn, pnpm and Bun install the same project, and what their lockfiles and layouts record.
How the JavaScript managers compare on speed and disk use, and how Corepack 3,816 pins one.
How resolution, hoisting, registries and OS package managers work.
How supply-chain attacks spread across ecosystems, and which defaults stop them.
Sections
- Why Package Managers Exist
- BookNest's Dependencies
- Yarn Classic and Yarn Berry
- pnpm's Store
- Bun as a Package Manager
- A Real Install Benchmark
- Corepack
- Bower and the Pre-npm Era
- Dependency Resolution
- Registries and Mirrors
- OS Package Managers on Linux
- macOS and Windows Managers
- Sandboxed Application Formats
- Other Ecosystems
- Supply-Chain Security
- Test Yourself!