npm Community Forum (Archive)

The npm community forum has been discontinued.

To discuss usage of npm, visit the GitHub Support Community.

npm installs unpublished packages

What I Wanted to Do

Install latest d-array published version ^1.0.0 (which is 1.2.4)

What Happened Instead

Installed version 1.3.0 (which does no longer exists).

Reproduction Steps

You have to have an older package-lock.json (see below) and just run npm install.


It’s possible to install an unpublished version of a package if you still have an older package-lock.json file which was referencing that version.
For example:

“name”: “d3arr”,
“version”: “1.0.0”,
“description”: “”,
“main”: “index.js”,
“scripts”: {
“test”: “echo “error: no test specified” && exit 1”
“author”: “”,
“license”: “isc”,
“dependencies”: {
“d3-array”: “^1.0.0”


“name”: “d3arr”,
“version”: “1.0.0”,
“lockfileversion”: 1,
“requires”: true,
“dependencies”: {
“d3-array”: {
“version”: “1.3.0”,
“resolved”: “”,
“integrity”: “sha512-synorys34ockyqwrlpuhk3xvgvdvjj6xlghjt/9ufvhaewr2pwb8heaavvc7g2lzfiqxti/oymjo0jxmr1oanw==”

Now if you run npm install, d-array@1.3.0 is installed, even if it doesn’t exist on npm oficial registry.

Platform Info

$ npm --versions
{ lge: '0.0.0',
  npm: '6.4.1',
  ares: '1.14.0',
  cldr: '33.1',
  http_parser: '2.8.0',
  icu: '62.1',
  modules: '64',
  napi: '3',
  nghttp2: '1.34.0',
  node: '10.13.0',
  openssl: '1.1.0i',
  tz: '2018e',
  unicode: '11.0',
  uv: '1.23.2',
  v8: '',
  zlib: '1.2.11' }

$ node -p process.platform

Does this still happen if you install with --cache /tmp/fresh-npm-cache?

Does this still happen if you install with --cache /tmp/fresh-npm-cache?

Yes, it is the same. d3-array version 1.3.0 is installed.
I also tried npm cache verify and npm cache clean --force – with the same result.