[BUG] npm update not respecting overrides in a workspace
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 10.1k
- Forks
- 4.7k
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 19
Description
Is there an existing issue for this?
- I have searched the existing issues
This issue exists in the latest npm version
- I am using the latest npm
Current Behavior
Unlike npm install, npm update is not respecting overrides in a workspace.
Expected Behavior
Expecting npm update to respect overrides the same way npm install does.
Steps To Reproduce
package.json
{
"workspaces": [
"alpha"
],
"overrides": {
"react-strict-dom": {
"react": "^19.1.0",
"react-dom": "^19.1.0"
}
}
}
alpha/package.json
{
"name": "alpha",
"version": "0.0.0",
"peerDependencies": {
"react": "^19.1.0",
"react-dom": "^19.1.0",
"react-native": "^0.79.1",
"react-strict-dom": "^0.0.34"
}
}
$ npm install
npm warn deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported
npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported
added 323 packages, and audited 325 packages in 10s
20 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
$ npm update
npm error code ERESOLVE
npm error ERESOLVE unable to resolve dependency tree
npm error
npm error While resolving: alpha@0.0.0
npm error Found: react@19.1.0
npm error node_modules/react
npm error peer react@"^19.1.0" from alpha@0.0.0
npm error alpha
npm error alpha@0.0.0
npm error node_modules/alpha
npm error workspace alpha from the root project
npm error peer react@"^19.1.0" from react-dom@19.1.0
npm error node_modules/react-dom
npm error peer react-dom@"^19.1.0" from alpha@0.0.0
npm error alpha
npm error alpha@0.0.0
npm error node_modules/alpha
npm error workspace alpha from the root project
npm error 1 more (react-native)
npm error
npm error Could not resolve dependency:
npm error peer react@"^18.2.0" from react-strict-dom@0.0.34
npm error node_modules/react-strict-dom
npm error peer react-strict-dom@"^0.0.34" from alpha@0.0.0
npm error alpha
npm error alpha@0.0.0
npm error node_modules/alpha
npm error workspace alpha from the root project
npm error
npm error Fix the upstream dependency conflict, or retry
npm error this command with --force or --legacy-peer-deps
npm error to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /Users/user/.npm/_logs/2025-04-25T22_13_08_681Z-eresolve-report.txt
npm error A complete log of this run can be found in: /Users/user/.npm/_logs/2025-04-25T22_13_08_681Z-debug-0.log
2025-04-25T22_13_08_681Z-debug-0.log
2025-04-25T22_13_08_681Z-eresolve-report.txt
Compared to when not using a workspace, overrides works fine:
{
"name": "alpha",
"version": "0.0.0",
"peerDependencies": {
"react": "^19.1.0",
"react-dom": "^19.1.0",
"react-native": "^0.79.1",
"react-strict-dom": "^0.0.34"
},
"overrides": {
"react-strict-dom": {
"react": "^19.1.0",
"react-dom": "^19.1.0"
}
}
}
$ npm install
npm warn deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported
npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported
added 322 packages, and audited 323 packages in 3s
20 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
$ npm update
up to date, audited 323 packages in 1s
20 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
Environment
- npm: 11.3.0
- Node.js: v23.11.0
- OS Name: macOS
- System Model Name: MBP M1
- npm config:
; "user" config from /Users/user/.npmrc
update-notifier = false
; node bin location = /Users/user/Library/Application Support/fnm/node-versions/v23.11.0/installation/bin/node
; node version = v23.11.0
; npm local prefix = /Users/user
; npm version = 11.3.0
; cwd = /Users/user
; HOME = /Users/user
; Run `npm config ls -l` to show all defaults.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the issue with the two package.json examples and compare npm install with npm update in the workspace and non-workspace cases. Trace how npm 11.3.0 resolves workspace overrides, then verify that npm update respects the root overrides without producing the reported ERESOLVE conflict.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- cli
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100