How to Easily Update NPM Dependencies with npm-check-updates (ncu)

Keeping project dependencies up to date is one of those routine maintenance tasks that can quickly become frustrating. When working on multiple applications, opening package.json to manually verify dozens of libraries against the npm registry is tedious, error-prone, and time-consuming.
The built-in npm outdated command helps you see what is behind, but it won't modify your package.json to latest major releases automatically.
That is why I rely on npm-check-updates (often abbreviated as ncu). It provides a fast, visual, and safe way to inspect, filter, and upgrade project dependencies across npm, pnpm, yarn, and bun.
In this guide, we will walk through how to install and use ncu, explore interactive mode, filter updates by semver targets, and manage monorepo workspaces safely.
Let's begin with running our first scan.
1. Checking for Updates with ncu 🔍
You do not even need to install npm-check-updates globally to try it out. You can run it directly using npx in any project folder:
npx npm-check-updatesIf you prefer having the global CLI command available anywhere on your machine, install it with:
npm install -g npm-check-updatesWhen you execute ncu in a project with outdated dependencies, it scans your package.json and outputs a color-coded summary:
$ ncu
Checking /Users/danyparedes/project/package.json
[====================] 14/14 100%
@types/node ^20.10.0 → ^22.13.0 (minor / major)
next ^14.2.0 → ^15.2.0 (major)
react ^18.3.1 → ^19.0.0 (major)
tailwindcss ^3.4.0 → ^4.0.0 (major)
zod ^3.22.4 → ^3.24.1 (patch)
Run ncu -u to upgrade package.jsonColor Coding Legend
- Green: Safe patch releases (e.g.
^3.22.0→^3.22.4). - Cyan / Yellow: Minor updates with new features (e.g.
^20.10.0→^20.14.0). - Red: Major breaking changes that require testing (e.g.
^18.0.0→^19.0.0).
Now that we know what packages need updating, let's look at how to write those updates to our package.json.
2. Upgrading package.json and Installing Dependencies 🚀
Running plain ncu only shows the differences—it does not touch your files.
To write the updated version strings directly into your package.json, use the -u (upgrade) flag:
# 1. Update package.json version strings
ncu -u
# 2. Install the new dependencies
npm installPro Tip: You can combine checking, writing, and installing in a single command using
ncu -ior pairing with your favorite package manager:
# For pnpm
ncu -u && pnpm install
# For Bun
ncu -u && bun install
# For Yarn
ncu -u && yarn installUpgrading everything at once might introduce breaking changes. Let's see how to control which semver levels to update.
3. Safe Target Upgrades (Patch & Minor Only) 🛡️
When preparing a production release or hotfix, you usually want bug fixes and minor features without risking major API breaks. npm-check-updates lets you define your target semver level using --target:
# Upgrade only patch versions (lowest risk)
ncu --target patch -u
# Upgrade minor + patch versions (no major breaks)
ncu --target minor -uSupported Targets Comparison
| Target Flag | Command Example | What Gets Updated | Risk Level |
|---|---|---|---|
latest (default) | ncu -u | Highest available version, including major releases | High (test required) |
minor | ncu --target minor -u | Highest minor/patch version within current major | Low / Medium |
patch | ncu --target patch -u | Highest patch release for current minor | Minimal |
greatest | ncu --target greatest -u | Includes prereleases / release candidates (beta, canary) | Experimental |
Now let's explore my favorite feature: interactive selection mode.
4. Interactive Mode (--interactive) 🎯
If you want granular control over which specific packages to bump, run ncu in interactive mode:
ncu --interactive --format groupThis launches a terminal UI where you can:
- Use arrow keys to navigate.
- Press
Spaceto toggle individual package selections. - Group packages logically by patch, minor, and major.
- Press
Enterto commit your selection.
? Choose which packages to update:
Patch (Safe bug fixes)
❯ ◯ zod ^3.22.0 → ^3.22.4
Minor (New features)
◯ @types/node ^20.10.0 → ^20.14.0
Major (Breaking changes)
◯ react ^18.3.1 → ^19.0.0
◯ next ^14.2.0 → ^15.2.0This workflow gives you complete clarity before making changes to your package.json.
Now, what if you want to update everything except a few specific packages? Let's look at filtering.
5. Filtering and Excluding Specific Packages 🎛️
You can filter package names using string matching, wildcards, or regular expressions.
Upgrading Only Specific Packages (--filter / -f)
# Update only React ecosystem dependencies
ncu -f "react*" -u
# Update only TypeScript and type definitions
ncu -f "@types/*,typescript" -uExcluding Risky Packages (--reject / -x)
If you want to keep a sensitive package at a pinned version, use --reject:
# Upgrade everything EXCEPT webpack and jest
ncu -x "webpack,jest" -uNext, let's look at how to run updates in monorepos.
6. Monorepo and Workspace Support (--workspaces) 🏢
If you manage a monorepo with Turborepo, Nx, or standard npm/pnpm/yarn workspaces, you don't need to cd into every package folder.
Run ncu with --workspaces (or -ws):
# Check all workspace packages
ncu --workspaces
# Interactively upgrade all workspaces at once
ncu --workspaces --interactiveTo update root dependencies in addition to workspace packages:
ncu --workspaces --root -u7. Useful Shortcut Scripts for Your package.json ⚡
To make dependency maintenance effortless for your entire team, add dedicated scripts to your root package.json:
{
"scripts": {
"deps:check": "npx npm-check-updates",
"deps:safe": "npx npm-check-updates --target minor -u && npm install",
"deps:interactive": "npx npm-check-updates --interactive --format group"
}
}Now, any developer on your team can run npm run deps:interactive to audit and update project dependencies without needing to memorize CLI flags.
Recap 🛠️
npm-check-updates turns an intimidating dependency upgrade process into a safe, controllable workflow:
ncu: Quick read-only scan of outdated packages.ncu -u: Writes latest versions topackage.json.ncu --target minor -u: Upgrades safe minor/patch versions without breaking changes.ncu -i --format group: Interactive picker to review upgrades package by package.ncu -ws: One-command updates across all monorepo workspaces.
For more Developer Experience and tooling tips, check out my articles on How to Detect and Fix Circular Dependencies in TypeScript and Migrating Next.js from Vercel to GCP Cloud Run!
Modern frontend development — Angular, React, TypeScript, accessibility, and performance.
Frequently Asked Questions
What is the difference between npm update and npm-check-updates (ncu)?
The standard npm update command respects version ranges defined in your package.json semver constraints (^ and ~), so it only installs non-breaking minor/patch versions. npm-check-updates (ncu) inspects the entire npm registry to find all available newer versions—including major breaking releases—and updates your package.json directly.
How do I upgrade only minor and patch versions without breaking major updates?
You can run 'ncu --target minor -u' or 'ncu --target patch -u'. This tells npm-check-updates to safely upgrade your packages to the highest compatible minor or patch version while strictly ignoring major breaking versions.
Does npm-check-updates support monorepos and workspaces?
Yes. You can run 'ncu --workspaces' (or 'ncu -ws') from the root of your monorepo. It will recursively inspect and update dependencies across all workspace packages in npm, pnpm, and yarn.
Does ncu work with other package managers like pnpm, yarn, and bun?
Yes. npm-check-updates automatically detects or allows you to specify your package manager using the '--packageManager' flag (e.g. 'ncu --packageManager pnpm' or 'ncu --packageManager bun').
Related Articles
How to Detect and Fix Circular Dependencies in TypeScript
Learn why circular dependencies break TypeScript applications at runtime, how to detect them using Madge and ESLint, and how to fix them using type-only imports and clean architectural patterns.
Moving from Vercel Next.js to Google Cloud Run: A Cost and Architecture Guide
Why I migrated my Next.js projects from Vercel to Google Cloud Run, how the standalone Docker build works, and how to stay on the free tier.
How to Check Types in TypeScript (The Complete Guide)
Learn how to check and validate types in TypeScript at compile-time and runtime using typeof, instanceof, the in operator, discriminated unions, custom type guards, and Zod or Valibot.
Share this article
If you found this guide helpful, consider sharing it with your team or fellow developers.
Real Software. Real Lessons.
I share the lessons I learned the hard way, so you can either avoid them or be ready when they happen.
Join 13,800+ developers and readers.
No spam ever. Unsubscribe at any time.