guide

Your npm cache is huge: how to shrink the npm, pnpm, yarn and bun caches

Quick answer

Start with the gentle one: npm cache verify checks the cache and garbage-collects data nothing points to any more. On our Mac it took the cache from 38.4 GB to 16.8 GB and kept all 15,025 packages. To empty it completely: npm cache clean --force (npm refuses without --force).

Where the caches are

ToolCacheGentleEmpty it
npm~/.npm/_cacachenpm cache verifynpm cache clean --force
pnpmrun pnpm store pathpnpm store prunedelete the store folder
yarn~/Library/Caches/Yarn (Yarn 1)noneyarn cache clean
bunrun bun pm cache in a projectnonebun pm cache rm

npm: verify first

npm cache verify

It reads the cache index, checks the data, and garbage-collects content no index entry uses. Its summary says how much it removed. On the Mac Sweep was built on: Content garbage-collected: 10236 (21525822320 bytes), and all 15,025 indexed packages were kept. Nothing you install later is affected.

If you want it all gone:

npm cache clean --force

Without --force npm only prints a note explaining that, since npm 5, the cache heals itself and clearing it is rarely needed.

pnpm: prune the store

pnpm's store is shared by every project on your Mac, and each project's node_modules hard-links into it. pnpm store prune removes packages that no project uses any more. In pnpm's own words, it "is not harmful and has no side effects on your projects".

yarn and bun

  • yarn: yarn cache clean empties the cache. With Yarn 2 and later the cache may live inside each project (.yarn/cache), and is often committed for zero-installs, so check before deleting that one.
  • bun: bun pm cache prints the cache folder and bun pm cache rm clears it.

Is it safe?

Yes. A cache is only a copy of what the registry already has. The cost is that the next install of each package downloads it again.

Questions

Is it safe to delete the npm cache?

Yes. It is a copy of packages from the registry. npm downloads anything it needs again on the next install.

What does npm cache verify do?

It checks the cache's integrity and garbage-collects content that no index entry references. Packages still in the index are kept.

Why does npm cache clean need --force?

Since npm 5 the cache detects and repairs corruption itself, so npm asks you to confirm that you really want to empty it.

Will deleting the cache delete node_modules?

No. Each project's node_modules is separate (except pnpm, whose node_modules link into the store; prune it rather than deleting it).