Executables in npm?
NPM is not just for distributing Node.js modules.
An NPM package can contain arbitrary stuff.
For example, NPM can be used to distribute executables.
NPM even has a few features to help with this use-case.
Let’s take a look.
Download the tarball for the rollup
package
and look inside:
$ wget https://registry.npmjs.org/rollup/-/rollup-2.28.2.tgz
$ tar -ztvf rollup-2.28.2.tgz
-rwxr-xr-x 0 0 0 71182 26 Oct 1985 package/dist/bin/rollup
-rw-r--r-- 0 0 0 167272 26 Oct 1985 package/dist/shared/index.js
-rw-r--r-- 0 0 0 524 26 Oct 1985 package/dist/loadConfigFile.js
...
The file at package/dist/bin/rollup
has its executable bit set.
When you run npm install rollup
,
this all gets copied into node_modules
,
and you can run the executable:
$ ls -l node_modules/rollup/dist/bin/rollup
-rwxr-xr-x 1 jim staff 71182 26 Oct 1985 node_modules/rollup/dist/bin/rollup
~/dev/tmp/rollup_hw
$ ./node_modules/rollup/dist/bin/rollup
rollup version 2.28.2
=====================================
Usage: rollup [options] <entry file>
...
Naturally enough, this executable is a node
script,
though it could be anything:
$ head -1 node_modules/rollup/dist/bin/rollup
However, it’s not recommended to run the script directly via this path.
When you npm install rollup
,
it also creates the symlink node_modules/.bin/rollup
:
$ ls -ahl node_modules/.bin/rollup
lrwxr-xr-x 1 jim staff 25B 30 Sep 11:35 node_modules/.bin/rollup -> ../rollup/dist/bin/rollup
This is created not because of the executable bit on the file,
but because rollup
’s package.json
has this config:
{
"bin": {
"rollup": "dist/bin/rollup"
}
}
But it’s not really recommended to run ./node_modules/.bin/rollup
directly, either.
One option is npm install rollup --global
, followed by just running rollup
.
This method is recommended by the rollup
docs, but it’s not very nice.
It assumes that npm install --global
puts the rollup
executable on the $PATH
(on my machine, this happens to work because nvm
sets this up).
It pollutes your $PATH
.
And it makes you forget to specify your dependencies in your package.json
.
A more reliable method is npm run-script
(or npm run
).
This reads commands from your local package.json
,
and runs them with node_modules/.bin
added to the PATH
.
For example, if we add this to our local package.json
:
{
"scripts": {
"build": "rollup main.mjs --file bundle.js"
}
}
Then we can run npm run-script build
,
which effectively runs ./node_modules/.bin/rollup main.mjs --file bundle.js
.
If you want to run this as a one-off command
instead of saving it to your scripts
,
you can run npx -c 'rollup main.mjs --file bundle.js'
.
Even more lazily, you can run npx foo bar baz
,
but this has quite a bit of magic.
First it looks for foo
on the path, e.g. npx ssh-keygen bar baz
will just run ssh-keygen bar baz
.
Failing that, it looks for ./node_modules/.bin/foo
.
If that doesn’t exist, it will try to install the package foo
(to a secret cache!),
and then “will try to guess the name of the binary to invoke”.
IMO, this is pretty dodgy behavior.
Similar posts
More by Jim
What does the dot do in JavaScript?
foo.bar
, foo.bar()
, or foo.bar = baz
- what do they mean? A deep dive into prototypical inheritance and getters/setters. 2020-11-01
Smear phishing: a new Android vulnerability
Trick Android to display an SMS as coming from any contact. Convincing phishing vuln, but still unpatched. 2020-08-06
A probabilistic pub quiz for nerds
A “true or false” quiz where you respond with your confidence level, and the optimal strategy is to report your true belief. 2020-04-26
Time is running out to catch COVID-19
Simulation shows it’s rational to deliberately infect yourself with COVID-19 early on to get treatment, but after healthcare capacity is exceeded, it’s better to avoid infection. Includes interactive parameters and visualizations. 2020-03-14
The inception bar: a new phishing method
A new phishing technique that displays a fake URL bar in Chrome for mobile. A key innovation is the “scroll jail” that traps the user in a fake browser. 2019-04-27
The hacker hype cycle
I got started with simple web development, but because enamored with increasingly esoteric programming concepts, leading to a “trough of hipster technologies” before returning to more productive work. 2019-03-23
Project C-43: the lost origins of asymmetric crypto
Bob invents asymmetric cryptography by playing loud white noise to obscure Alice’s message, which he can cancel out but an eavesdropper cannot. This idea, published in 1944 by Walter Koenig Jr., is the forgotten origin of asymmetric crypto. 2019-02-16
How Hacker News stays interesting
Hacker News buried my post on conspiracy theories in my family due to overheated discussion, not censorship. Moderation keeps the site focused on interesting technical content. 2019-01-26
My parents are Flat-Earthers
For decades, my parents have been working up to Flat-Earther beliefs. From Egyptology to Jehovah’s Witnesses to theories that human built the Moon billions of years in the future. Surprisingly, it doesn’t affect their successful lives very much. For me, it’s a fun family pastime. 2019-01-20
The dots do matter: how to scam a Gmail user
Gmail’s “dots don’t matter” feature lets scammers create an account on, say, Netflix, with your email address but different dots. Results in convincing phishing emails. 2018-04-07
The sorry state of OpenSSL usability
OpenSSL’s inadequate documentation, confusing key formats, and deprecated interfaces make it difficult to use, despite its importance. 2017-12-02
I hate telephones
I hate telephones. Some rational reasons: lack of authentication, no spam filtering, forced synchronous communication. But also just a visceral fear. 2017-11-08
The Three Ts of Time, Thought and Typing: measuring cost on the web
Businesses often tout “free” services, but the real costs come in terms of time, thought, and typing required from users. Reducing these “Three Ts” is key to improving sign-up flows and increasing conversions. 2017-10-26
Granddad died today
Granddad died. The unspoken practice of death-by-dehydration in the NHS. The Liverpool Care Pathway. Assisted dying in the UK. The importance of planning in end-of-life care. 2017-05-19
How do I call a program in C, setting up standard pipes?
A C function to create a new process, set up its standard input/output/error pipes, and return a struct containing the process ID and pipe file descriptors. 2017-02-17
Your syntax highlighter is wrong
Syntax highlighters make value judgments about code. Most highlighters judge that comments are cruft, and try to hide them. Most diff viewers judge that code deletions are bad. 2014-05-11
Want to build a fantastic product using LLMs? I work at
Granola where we're building the future IDE for knowledge work. Come and work with us!
Read more or
get in touch! This page copyright James Fisher 2020. Content is not associated with my employer. Found an error? Edit this page.