# How to Update Dependencies in the Insomnia Project Using package.json

> Easily update dependencies in the Insomnia project by editing package.json and running npm install. Learn how to manage your project's package.json efficiently.

- Repository: [Kong/insomnia](https://github.com/Kong/insomnia)
- Tags: how-to-guide
- Published: 2026-06-27

---

**To update dependencies in the Insomnia project, edit the version string in the target workspace's [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) and run `npm install` from the repository root, or use `npm install <package>@latest -w <workspace>` to programmatically update while respecting the monorepo's workspace deduplication.**

The Kong/insomnia repository is an Electron-based monorepo that manages related packages through **npm workspaces**. When you need to update dependencies in the Insomnia project using [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json), understanding this architecture is critical to maintaining consistent dependency resolution across the main application and shared libraries.

## Understanding the Insomnia Monorepo Structure

The Insomnia project uses a workspace-based organization where dependency management is distributed across multiple [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) files.

### Root package.json vs. Workspace package.json

In the repository root, [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) primarily defines the workspaces array and top-level development dependencies. According to the Kong/insomnia source code, the bulk of runtime dependencies for the Electron application reside in [`packages/insomnia/package.json`](https://github.com/Kong/insomnia/blob/main/packages/insomnia/package.json). This distinction matters because you must target the correct workspace when updating dependencies to ensure the changes apply to the main app rather than the root configuration.

The workspace configuration ensures that shared dependencies are deduplicated across the monorepo, keeping the final Electron bundle size optimized.

## How to Update Dependencies in the Insomnia Project Using package.json

### Method 1: Manual Version Updates

For precise control over semantic versioning, manually edit the dependency version in the appropriate workspace:

1. Open [`packages/insomnia/package.json`](https://github.com/Kong/insomnia/blob/main/packages/insomnia/package.json) for the main application
2. Locate the package in `dependencies` or `devDependencies`
3. Update the version string (e.g., change `"^2.4.0"` to `"^3.0.0"`)
4. Run the installation command from the repository root:

```bash
npm install -w insomnia

```

This approach is essential when upgrading to a new major version that contains breaking changes, as it allows you to specify the exact semver range.

### Method 2: Command-Line Updates

Use npm's built-in commands to query and update packages programmatically:

**Check for outdated dependencies:**

```bash
npm outdated -w insomnia

```

**Update a specific package to the latest version:**

```bash
npm install react@latest -w insomnia

```

**Update all packages to the newest versions allowed by existing semver ranges:**

```bash
npm update -w insomnia

```

The `-w insomnia` flag (or `--workspace=insomnia`) ensures npm targets the correct workspace defined in the root [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json), preventing the dependency from being installed at the root level.

### Clean Installation After Major Updates

When upgrading across major versions or troubleshooting dependency conflicts, perform a clean install:

```bash
rm -rf node_modules
npm ci

```

The `npm ci` command respects the [`package-lock.json`](https://github.com/Kong/insomnia/blob/main/package-lock.json) lockfile and installs all workspaces according to their exact specified versions, ensuring reproducible builds.

## Validating Dependency Updates in the Insomnia Monorepo

After modifying [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) and installing updates, validate the changes to catch API-breaking changes early:

```bash
npm run lint
npm run type-check
npm test

```

Insomnia ships with a comprehensive test matrix including unit and E2E tests. Running these commands ensures that the updated dependencies do not introduce type errors or break existing functionality. Always commit both the modified [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) and the updated [`package-lock.json`](https://github.com/Kong/insomnia/blob/main/package-lock.json) to version control, as the lockfile pins the exact resolved versions for all workspaces.

## Summary

- **Identify the correct workspace**: Runtime dependencies for the main Electron app live in [`packages/insomnia/package.json`](https://github.com/Kong/insomnia/blob/main/packages/insomnia/package.json), not the repository root.
- **Use workspace-specific commands**: Append `-w insomnia` to npm commands to target the main application workspace.
- **Manual editing for major versions**: Edit [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) directly when upgrading across major versions, then run `npm install -w insomnia`.
- **Commit the lockfile**: Always include [`package-lock.json`](https://github.com/Kong/insomnia/blob/main/package-lock.json) changes when committing dependency updates to ensure consistent installations across environments.
- **Validate thoroughly**: Run the lint, type-check, and test suites to verify compatibility after updates.

## Frequently Asked Questions

### Where is the main package.json located in the Insomnia project?

The primary [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) for the Electron application is located at [`packages/insomnia/package.json`](https://github.com/Kong/insomnia/blob/main/packages/insomnia/package.json). The repository root contains a separate [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json) that configures npm workspaces and defines repository-level scripts, but it does not contain the application's runtime dependencies.

### How do I update a dependency only in the main Insomnia app workspace?

Use the `-w insomnia` flag with npm commands. For example, `npm install <package>@latest -w insomnia` updates the specific package only in the `packages/insomnia` workspace, leaving other workspaces unaffected. This follows the workspace isolation patterns defined in the Kong/insomnia monorepo structure.

### Why must I commit the package-lock.json when updating dependencies?

The [`package-lock.json`](https://github.com/Kong/insomnia/blob/main/package-lock.json) file is version-controlled in the Insomnia repository to ensure that all developers and CI environments install exactly the same dependency tree. When you update [`package.json`](https://github.com/Kong/insomnia/blob/main/package.json), the lockfile captures the exact resolved versions, including deduplicated shared dependencies across workspaces, preventing "works on my machine" issues.

### How do I check for outdated dependencies before updating?

Run `npm outdated -w insomnia` from the repository root. This command displays a table showing the current installed version, the wanted version (latest satisfying the semver range), and the latest available version for each dependency in the main workspace, allowing you to assess update safety before making changes.