# How to Manage Dependencies in munder-difflin: A Complete Guide for Electron Projects

> Learn to manage dependencies in munder-difflin for Electron projects. This guide covers using npm commands and package json for reproducible builds. Essential for developers.

- Repository: [Chaitanya Giri/munder-difflin](https://github.com/chaitanyagiri/munder-difflin)
- Tags: how-to-guide
- Published: 2026-08-20

---

**Use standard npm commands with [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json) as the single source of truth, and always commit both [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json) and [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json) after any change to ensure reproducible builds.**

The `munder-difflin` repository is a modern Electron-based TypeScript application that follows standard Node.js dependency management practices. Understanding how to properly manage dependencies in munder-difflin is essential for maintaining build reproducibility and runtime stability across development environments.

## Where Dependencies Are Declared

All dependencies in munder-difflin are centralized in the root [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json) file. This single file declares both **runtime dependencies** under `"dependencies"` and **development tools** under `"devDependencies"` 【source 1†https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json#L29-L62】.

Key runtime libraries include:

- `electron@^32.2.0` — the core Electron framework
- `better-sqlite3` — native SQLite bindings for the main process
- `node-pty` — pseudo-terminal emulation
- [`pixi.js`](https://github.com/chaitanyagiri/munder-difflin/blob/main/pixi.js) — 2D graphics rendering
- `@codemirror/*` packages — code editor functionality
- `@monaco-editor/react` — Monaco editor React wrapper

Development dependencies include `typescript`, `vite`, `electron-builder`, and `@electron/rebuild` — tools that are **not** bundled into the final application.

## Essential npm Commands for Managing Dependencies

| Goal | Command | Result |
|------|---------|--------|
| Add runtime library | `npm install <pkg>@<version>` | Updates `"dependencies"` and [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json) |
| Add development tool | `npm install -D <pkg>@<version>` | Updates `"devDependencies"` and lockfile |
| Upgrade existing package | `npm update <pkg>` | Bumps to latest semver-compatible version |
| Remove package | `npm uninstall <pkg>` | Cleans entry from both files |
| Exact lockfile install | `npm ci` | Reproducible install for CI pipelines |
| Security audit | `npm audit` | Scans for known vulnerabilities |
| Check outdated | `npm outdated` | Lists available updates |

Any modification to dependencies requires committing both [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json) and [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json) to maintain reproducible builds.

## Practical Code Examples

Install a new runtime dependency:

```bash
npm install lodash@^4.17.21

```

This inserts the package into the `"dependencies"` section and regenerates [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json).

Add a development-only tool:

```bash
npm install -D eslint@^9.0.0

```

The `-D` flag ensures the package lands in `"devDependencies"` and won't ship with the final Electron binary.

Upgrade an existing Codemirror language package:

```bash
npm install @codemirror/lang-json@latest

```

Remove an unused package completely:

```bash
npm uninstall tunnelmole

```

For CI environments, use the exact lockfile state:

```bash
npm ci

```

This command deletes `node_modules` and reinstalls precisely the versions recorded in [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json).

## Handling Native Module Rebuilds

The munder-difflin project depends on native modules like `better-sqlite3` and `node-pty` that must be compiled for the specific Electron runtime version. The `postinstall` script handles this automatically 【source 1†https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json#L18-L20】:

```bash
npm run postinstall

```

This executes:

```bash
electron-rebuild -f && node tools/ensure-pty-perms.cjs && node tools/patch-node-pty-conpty.cjs

```

The `electron-rebuild -f` flag forces a rebuild of all native modules. Subsequent scripts ensure proper permissions and apply necessary patches to `node-pty`. Run this manually after any dependency change that affects native modules, or let it trigger automatically after `npm install`.

## Key Architecture Considerations

**Main process dependencies** (`better-sqlite3`, `node-pty`, [`pixi.js`](https://github.com/chaitanyagiri/munder-difflin/blob/main/pixi.js)) are imported directly by [`out/main/index.js`](https://github.com/chaitanyagiri/munder-difflin/blob/main/out/main/index.js) and must be present before the Electron rebuild step completes.

**Renderer process dependencies** (React components, Monaco editor, Codemirror) are pure JavaScript/TypeScript modules bundled by Vite during `npm run dev` or `npm run build`. These don't require native rebuilds.

**Development tools** live exclusively in `"devDependencies"` and never reach the packaged application, keeping the runtime bundle lean.

## Critical Files in the Dependency Workflow

| File | Purpose |
|------|---------|
| [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json) | Declares all dependencies and devDependencies with version constraints |
| [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json) | Locks exact resolved versions for reproducible installs |
| [`electron-builder.yml`](https://github.com/chaitanyagiri/munder-difflin/blob/main/electron-builder.yml) | Configures packaging to include only runtime dependencies |
| [`tsconfig.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/tsconfig.json) | Affects module resolution for TypeScript imports |
| `tools/postinstall.cjs` | Rebuilds native modules for the Electron runtime |

## Summary

- Manage dependencies in munder-difflin through standard npm commands against the root [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json)
- Always commit both [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json) and [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json) after any dependency change
- Use `npm install -D` for build tools; plain `npm install` for runtime libraries
- Run `npm ci` in CI pipelines for deterministic builds
- Native modules rebuild automatically via the `postinstall` script or `electron-rebuild`

## Frequently Asked Questions

### What is the difference between dependencies and devDependencies in munder-difflin?

**Dependencies** are runtime libraries shipped with the Electron application — including `electron`, `better-sqlite3`, `node-pty`, and UI packages like [`pixi.js`](https://github.com/chaitanyagiri/munder-difflin/blob/main/pixi.js). **DevDependencies** are build-time tools including `typescript`, `vite`, and `electron-builder` that never reach the final package. This separation keeps the distributed application size minimal.

### How do I add a package that requires native compilation?

Install it normally with `npm install <pkg>`, then ensure the `postinstall` script runs. The project's configuration automatically triggers `electron-rebuild` to compile native modules for the current Electron version. For manual verification, run `npm run postinstall` after installation.

### Why must I commit package-lock.json after changing dependencies?

The [`package-lock.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package-lock.json) file records the exact resolved versions of every dependency in the tree, including transitive dependencies. Without it, different `npm install` runs could resolve different versions, causing "works on my machine" failures. Committing this file guarantees identical `node_modules` across all environments.

### What should I do if npm audit reports vulnerabilities in munder-difflin?

Run `npm audit fix` to automatically upgrade to non-vulnerable versions where possible. For breaking changes, review the advisory details and manually update the package version in [`package.json`](https://github.com/chaitanyagiri/munder-difflin/blob/main/package.json), then test thoroughly. Always run the full build and verify the `postinstall` native rebuild succeeds before committing.