Clean up package.json for publishing.
Your package.json:
{
"name": "...",
"version": "...",
"description": "...",
"scripts": {
"test": "...",
"coverage": "...",
"build": "...",
"prepack": "npm run build && publish-util-prepack",
"postpack": "publish-util-postpack"
},
"publishUtil": {
"remove": ["devDependencies", { "scripts": ["test", "coverage", "build"] }],
"keep": ["options"]
},
"dependencies": {
"react": "^17.0.0",
"react-dom": "^17.0.0"
},
"devDependencies": {
"tap": "^15.0.0",
"publish-util": "^1.0.0"
},
"nyc": {
"reporter": ["lcov", "text", "text-summary"]
},
"options": {}
}
Your package.json published:
{
"name": "...",
"version": "...",
"description": "...",
"scripts": {
"postpack": "publish-util-postpack"
},
"dependencies": {
"react": "^17.0.0",
"react-dom": "^17.0.0"
},
"options": {}
}
devDependencies is gone here only because publishUtil.remove asks for it - by default it's kept.
Just install this to your module:
npm install --save-dev publish-util
It will automatically add prepack and postpack scripts to your package.json for you.
Out of the box it will clean up non-standard fields plus workspaces from your package.json. The dependency fields, including devDependencies, are kept because npmjs.com uses them to show what your package depends on. To remove devDependencies, see details below
This module offers a custom publishing script to fix some behaviors of npm publish.
The problem is that before any thing can process package.json, npm publish will load and upload it to the registry as packument (meta for the package).
If you want the copy of package.json after this module processed it to be the packument meta, then use the do-publish command:
npx do-publish
The script use whatever version of npm you have to do the actual work. It takes all CLI arguments that npm publish accepts and will pass them through.
publishUtil configs:You can configure some behaviors with publishUtil in your package.json.
| Config | Description | Default |
|---|---|---|
rename |
object map of keys to rename from package.json - done before remove |
|
remove |
array of keys and nesting keys to remove from package.json |
|
keep |
array of keys and nesting keys to keep from package.json. |
|
removeExtraKeys |
remove top level non-standard fields. | true |
autoPostPack |
insert scripts.postpack if it's missing. |
true |
silent |
don't log message with console | false |
publishUtil is removed automatically.
rename details. The rename config is an object map, with key being the field to rename, and its value being the target name.
For example:
{
"publishUtil": {
"rename": {
"scripts.foo": "scripts.renamedFoo"
}
}
}
scripts.prepublishOnly is removed automatically if it's just "publish-util-prepublishonly". Add it to publishUtil.keep to keep it:{
"publishUtil": {
"keep": [{ "scripts": ["prepublishOnly"] }]
}
}
scripts.prepack is removed automatically if it runs publish-util-prepack, alone or chained like "npm run build && publish-util-prepack".
publish-util-prepublishonly is the legacy hook from when pruning ran in prepublishOnly. It skips when scripts.prepack already runs publish-util-prepack, so npm publish doesn't prune twice.
Can't remove scripts.postpack because npm needs that to restore package.json.
Can't use prepack because npm publish uploads meta data before that so if you want to publish with different dependencies it will break.
remove and keep formatsThe config remove and keep can be:
"/<regexp>/<flags>"For example, to reach pkg.key1.key2, and pkg.key1.xyz*:
[
{
"key1": ["key2", "/xyz.*/"]
}
]
These top level fields are considered standard fields:
workspacesmoduleAny extra top level fields not in the standard fields are automatically removed.
publishUtil.removeExtraKeys to false.publishUtil.keep to avoid them being removed.devDependencies is a standard field so it's kept. To drop it from your published package.json, list it in publishUtil.remove:
{
"publishUtil": {
"remove": ["devDependencies"]
}
}
postpack InsertIf you don't have a scripts.postpack, then it's automatically added with "publish-util-postpack" to ensure your package.json is restored after packing.
publishUtil.autoPostPack to false to skip this.Packs of the same package share one backup of package.json in the OS temp dir. Only the last pack to finish restores it. Each pack is recorded with the pid of the process running it, such as npm, so a killed pack is not waited on. The next prepack or postpack restores what it left pruned. Where the process table can't be read (no ps, as on Windows), a killed pack is still counted as active.
To verify package.json content.
npm run prepackpackage.json to ensure everything is in ordernpm run postpack to restore package.jsonpackage.json againUsing npm pack
npm packpackage.json to ensure it's not modified.tgz file and extract itpackage/package.json to ensure it's as expected.See the full API reference for every bin, config setting, function, and type.