Semantic Versioning using npm
By Flavio Copes
Learn Semantic Versioning in npm: how the major.minor.patch numbers work and how the ^ and ~ range symbols control which versions npm update will install.
If there’s one great thing in Node.js packages, is that all agreed on using Semantic Versioning for their version numbering.
The Semantic Versioning concept is simple: all versions have 3 digits: x.y.z.
- the first digit is the major version
- the second digit is the minor version
- the third digit is the patch version
When you make a new release, you don’t just up a number as you please, but you have rules:
- you up the major version when you make incompatible API changes
- you up the minor version when you add functionality in a backward-compatible manner
- you up the patch version when you make backward-compatible bug fixes
The convention is adopted all across programming languages, and it is very important that every npm package adheres to it, because the whole system depends on that.
Why is that so important?
Because npm set some rules we can use in the package.json file to choose which versions it can update our packages to, when we run npm update (more on that in how to update all the Node dependencies).
The rules use those symbols:
^~>>=<<==-||
Let’s see those rules in detail:
^: if you write^1.2.3, when runningnpm updateit can update to patch and minor releases:1.2.4,1.3.0and so on, but not2.0.0.~: if you write~0.13.0, when runningnpm updateit can update to patch releases:0.13.1is ok, but0.14.0is not.>: you accept any version higher than the one you specify>=: you accept any version equal to or higher than the one you specify<=: you accept any version equal or lower to the one you specify<: you accept any version lower to the one you specify=: you accept that exact version-: you accept a range of versions. Example:2.1.0 - 2.6.2||: you combine sets. Example:< 2.1 || > 2.6
The ^ works differently on 0.x versions. The rule is that it never changes the left-most number that isn’t zero. So ^0.13.0 only allows patch releases like 0.13.1, not 0.14.0, and ^0.0.4 allows only 0.0.4.
^ is the one you’ll see most often, because npm install <package-name> saves new dependencies in package.json with a ^ range by default.
You can combine some of those notations, for example use 1.0.0 || >=1.1.0 <1.2.0 to either use 1.0.0 or one release from 1.1.0 up, but lower than 1.2.0.
There are other rules, too:
- no symbol: you accept only that specific version you specify (
1.2.1) latest: this isn’t a range but a dist-tag. It points to the version the package author marked as the current release, the one npm installs by default. It can jump to a new major version, so use it with care
I also built a free semver advisor that tells you which version number to bump and explains what the ^ and ~ ranges allow.
Want me to talk about your product? You can sponsor this site.
Related posts about node: