How to Update Dependencies in the Insomnia Project Using package.json

To update dependencies in the Insomnia project, edit the version string in the target workspace's package.json and run npm install from the repository root, or use npm install <package>@latest -w <workspace> to programmatically update while respecting the monorepo's workspace deduplication.

The Kong/insomnia repository is an Electron-based monorepo that manages related packages through npm workspaces. When you need to update dependencies in the Insomnia project using package.json, understanding this architecture is critical to maintaining consistent dependency resolution across the main application and shared libraries.

Understanding the Insomnia Monorepo Structure

The Insomnia project uses a workspace-based organization where dependency management is distributed across multiple package.json files.

Root package.json vs. Workspace package.json

In the repository root, package.json primarily defines the workspaces array and top-level development dependencies. According to the Kong/insomnia source code, the bulk of runtime dependencies for the Electron application reside in packages/insomnia/package.json. This distinction matters because you must target the correct workspace when updating dependencies to ensure the changes apply to the main app rather than the root configuration.

The workspace configuration ensures that shared dependencies are deduplicated across the monorepo, keeping the final Electron bundle size optimized.

How to Update Dependencies in the Insomnia Project Using package.json

Method 1: Manual Version Updates

For precise control over semantic versioning, manually edit the dependency version in the appropriate workspace:

  1. Open packages/insomnia/package.json for the main application
  2. Locate the package in dependencies or devDependencies
  3. Update the version string (e.g., change "^2.4.0" to "^3.0.0")
  4. Run the installation command from the repository root:
npm install -w insomnia

This approach is essential when upgrading to a new major version that contains breaking changes, as it allows you to specify the exact semver range.

Method 2: Command-Line Updates

Use npm's built-in commands to query and update packages programmatically:

Check for outdated dependencies:

npm outdated -w insomnia

Update a specific package to the latest version:

npm install react@latest -w insomnia

Update all packages to the newest versions allowed by existing semver ranges:

npm update -w insomnia

The -w insomnia flag (or --workspace=insomnia) ensures npm targets the correct workspace defined in the root package.json, preventing the dependency from being installed at the root level.

Clean Installation After Major Updates

When upgrading across major versions or troubleshooting dependency conflicts, perform a clean install:

rm -rf node_modules
npm ci

The npm ci command respects the package-lock.json lockfile and installs all workspaces according to their exact specified versions, ensuring reproducible builds.

Validating Dependency Updates in the Insomnia Monorepo

After modifying package.json and installing updates, validate the changes to catch API-breaking changes early:

npm run lint
npm run type-check
npm test

Insomnia ships with a comprehensive test matrix including unit and E2E tests. Running these commands ensures that the updated dependencies do not introduce type errors or break existing functionality. Always commit both the modified package.json and the updated package-lock.json to version control, as the lockfile pins the exact resolved versions for all workspaces.

Summary

  • Identify the correct workspace: Runtime dependencies for the main Electron app live in packages/insomnia/package.json, not the repository root.
  • Use workspace-specific commands: Append -w insomnia to npm commands to target the main application workspace.
  • Manual editing for major versions: Edit package.json directly when upgrading across major versions, then run npm install -w insomnia.
  • Commit the lockfile: Always include package-lock.json changes when committing dependency updates to ensure consistent installations across environments.
  • Validate thoroughly: Run the lint, type-check, and test suites to verify compatibility after updates.

Frequently Asked Questions

Where is the main package.json located in the Insomnia project?

The primary package.json for the Electron application is located at packages/insomnia/package.json. The repository root contains a separate package.json that configures npm workspaces and defines repository-level scripts, but it does not contain the application's runtime dependencies.

How do I update a dependency only in the main Insomnia app workspace?

Use the -w insomnia flag with npm commands. For example, npm install <package>@latest -w insomnia updates the specific package only in the packages/insomnia workspace, leaving other workspaces unaffected. This follows the workspace isolation patterns defined in the Kong/insomnia monorepo structure.

Why must I commit the package-lock.json when updating dependencies?

The package-lock.json file is version-controlled in the Insomnia repository to ensure that all developers and CI environments install exactly the same dependency tree. When you update package.json, the lockfile captures the exact resolved versions, including deduplicated shared dependencies across workspaces, preventing "works on my machine" issues.

How do I check for outdated dependencies before updating?

Run npm outdated -w insomnia from the repository root. This command displays a table showing the current installed version, the wanted version (latest satisfying the semver range), and the latest available version for each dependency in the main workspace, allowing you to assess update safety before making changes.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →