npm, yarn and pnpm do the same job: they install the libraries your project needs. The short answer: use the package manager the project was created with, and only that one. The giveaway is the lockfile already sitting there. Mixing managers is the easiest way to end up with a site that works on your computer and fails on the server, because each one resolves versions in its own way.
How to tell which one your project uses
| Lockfile |
Manager |
Exact install, for repeating |
package-lock.json |
npm |
npm ci |
yarn.lock |
yarn |
yarn install --frozen-lockfile (in classic yarn) |
pnpm-lock.yaml |
pnpm |
pnpm install --frozen-lockfile |
The lockfile records the exact version of every library that worked. Whoever installs from it gets what you tested; whoever installs without it gets the newest versions package.json allows, and that can be something else. Always keep it in the repository.
In cPanel
The “Run NPM Install” button in “Setup Node.js App” uses npm. If your project uses yarn or pnpm, you have two honest options: build on your computer and upload only the result, or, if the account has a terminal, enter the application’s environment (the command is at the top of the screen) and check with yarn -v or pnpm -v whether the tool exists before counting on it. Do not install global tools with sudo: a shared account has no root. Node.js in cPanel: choosing the version and using npm explains the environment.
On a VPS, step by step
| 1 |
See what the project asks for. In package.json the packageManager field, when present, names the manager and its version.
|
|
| 2 |
Enable Corepack, which ships with most Node versions and installs the right yarn or pnpm: corepack enableIf your Node does not include it, install the manager the way its own documentation says. When in doubt, stay with npm, which is already there.
|
|
| 3 |
Install from the lockfile, with the command in the table above, rather than a plain install when you want to repeat a known state.
|
|
| 4 |
If you change manager, delete the old lockfile and the node_modules folder, install with the new one, and commit the new file. Never leave two lockfiles in one project.
|
|
Two lockfiles, two truths. If the repository has both package-lock.json and yarn.lock, each person and each server ends up with different versions, and the “works here” error appears with no visible cause. Pick one, delete the other and tell the team.
|
On a shared account, watch the file count. Any manager fills node_modules with thousands of small files, and the account has an inode limit: the limits nobody advertises. Installing only what production needs (npm ci --omit=dev) helps. If the install fails, see npm install errors.
|
|
Need a server where you can install whatever tools you like? Have a look at our VPS plans.
See the VPS servers
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon) See plans |