How does npm and package-lock.json behave, with respect to different operating systems/CPU architectures?
18:48 13 Nov 2025

My understanding is that:

1. There are certain NPM packages that are intended only for use on certain operating systems.

For example fsevents is only for MacOS - it's for listening to file changes in a directory tree.

The os and cpu properties of package.json can be used to mark said packages this way.

2. The purpose of a package-lock.json is to the exact same dependencies be installed on each run of npm i - this way you don't have 100 different developers all working with 100 different versions of dependencies and constant 'it works on my machine' type problems.

Something I've never understood - is how does this work as it relates to an application that might be being built by some users on MacOS and others on Windows?

1. What happens if a dependency is required and but the host operating system does not match? Does NPM just error?
Does that mean that all OS specific packages should always be marked as optional (or else the consuming package itself be marked as OS specific).

I note that Vite for example marks fsevents as an optional dependency.

Or does the package get installed, and it's up to the consuming code to detect OS/CPU architecture and use/not use it?

2. What happens to the package-lock.json when two different operating systems install the dependencies?

I assume that you wouldn't have a situation where the package-lock keeps changing between different OS installation runs.

npm package-lock.json