ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 74

  1. Blog

ncu vs npm outdated: 4 Majors Beyond Wanted

npm-check-updates 23.1.0 vs npm outdated on 7 stale deps (axios/eslint/lodash/prettier/react/typescript/vite): ncu proposed 4 majors (React 19, Vite 8, TypeScript 7, ESLint 10) while npm Wanted stayed in-range; wall medians 863 ms vs 783 ms.

Aditya Challa·5 October 2026·5 min read

Hands-on
On this page
  1. What I tested
  2. What does ncu show that npm outdated does not?
  3. Is ncu faster than npm outdated?
  4. Should you add ncu to the workflow?
  5. Sources
  6. Related

I ran npm-check-updates (ncu) 23.1.0 and npm outdated on the same package.json with seven intentionally stale deps: ncu proposed four major bumps (React 18 to 19, Vite 5 to 8, TypeScript 5 to 7, ESLint 8 to 10), while npm's Wanted column stayed inside the current major for those four. Wall-clock medians were close: ncu 863 ms, npm outdated 783 ms.

Short answer: use ncu when you want package.json ranges moved to latest, including breaking majors. Use npm outdated when you only want what a normal npm update can install inside today's ranges. No affiliate links in this post.

What I tested

  • Machine: 8 vCPU Intel Xeon / 15 GB RAM Linux cloud box, Node 20.19.2 / npm 9.2.0, tested 5 Oct 2026 (about 23:47 to 23:52 IST). Shared box; seven interleaved rounds per command after one warmup each.
  • Fixture: /workspace/bench-ncu/package.json with axios 1.6.0, eslint 8.57.0, lodash 4.17.21, prettier 3.2.5, react 18.2.0, typescript 5.4.5, vite 5.2.0 (plus ncu itself installed locally).
  • Commands: npx npm-check-updates (human table), npm outdated (human table). Separate JSON-oriented runs were timed but not used for the major-count story (ncu --format json is invalid on 23.1; use other --format values).
  • Timing: process wall clock via performance.now() around a fresh child process. Medians: ncu 863 ms, npm outdated 783 ms (npm exits 1 when anything is outdated; that is normal).
  • Findings: ncu grouped three minor bumps and four majors. For the four majors, npm Wanted stayed on 18.3.1 / 5.4.21 / 5.9.3 / 8.57.1 while Latest matched ncu's targets (19.3.0 / 8.3.2 / 7.0.2 / 10.12.0).
  • One surprise: people treat ncu as "faster outdated," but on this box it was slightly slower. The useful difference was the Wanted-versus-latest view, not the milliseconds.
  • Not tested: ncu -u writing package.json, monorepo / workspaces mode, pnpm or Yarn adapters, interactive reject filters, CI fail-on-major scripts, Windows/macOS.

What does ncu show that npm outdated does not?

PackageLockednpm Wantednpm Latest / ncu targetGap
react18.2.018.3.119.3.0major only in ncu / Latest
vite5.2.05.4.218.3.2major only in ncu / Latest
typescript5.4.55.9.37.0.2major only in ncu / Latest
eslint8.57.08.57.110.12.0major only in ncu / Latest
axios1.6.01.20.01.20.0same minor
lodash4.17.214.18.14.18.1same minor
prettier3.2.53.9.93.9.9same minor

npm outdated already prints Latest. What it will not do is treat Latest as the upgrade you get from npm update. Wanted is the ceiling of your current range. ncu's default table is a proposal to rewrite those ranges. That is why teams say "ncu found majors npm hid": Wanted hid them, Latest did not.

If you are deciding whether TypeScript 7 is even worth chasing after ncu lists it, see the TypeScript 7 upgrade post. For keeping versions aligned across packages, see syncpack vs npm-check.

Is ncu faster than npm outdated?

CommandMedian wall clock (7 runs)
ncu 23.1.0863 ms
npm outdated783 ms

No, not here. The gap is noise next to registry latency. Do not pick ncu for speed.

Should you add ncu to the workflow?

SituationMy pick
Monthly "what majors are we behind on?" reviewncu
Safe npm update preview inside current rangesnpm outdated
CI that fails when Wanted movesnpm outdated --json
CI that fails when Latest is a new majorncu (or compare Latest yourself)
You already run syncpack / Renovate for rangesOptional; ncu is redundant

Bottom line: on seven stale deps, ncu proposed four majors that npm Wanted never suggested. Who should skip ncu: repos that must not rewrite ranges by hand and already trust Renovate or Dependabot pull requests for majors. For unused-dependency cleanup after upgrades, see knip vs depcheck; for runtime package managers around those installs, see pnpm vs npm vs Bun; for a current Vite major after ncu flags it, see the Vite 8.3.2 post.

How this was made: I pinned seven old deps on the ShopperCove test box, ran interleaved ncu and npm outdated processes, saved the tables and timings to JSON, and checked the write-up against that output with AI drafting help.

Sources

  • https://github.com/raineorshine/npm-check-updates
  • https://www.npmjs.com/package/npm-check-updates
  • https://docs.npmjs.com/cli/v9/commands/npm-outdated
  • https://docs.npmjs.com/cli/v9/commands/npm-update

Related

  • https://www.shoppercove.com/blog/syncpack-vs-npm-check
  • https://www.shoppercove.com/blog/typescript-7-should-you-upgrade
  • https://www.shoppercove.com/blog/knip-vs-depcheck
  • https://www.shoppercove.com/blog/pnpm-vs-npm-vs-bun
  • https://www.shoppercove.com/blog/vite-8-3-2-renderbuilturl-bundled-dev-sourcemaps-october-2026
  • https://www.shoppercove.com/blog/oxlint-vs-eslint
  • https://www.shoppercove.com/blog/lefthook-vs-husky
  • https://www.shoppercove.com/blog/volta-vs-fnm
ncunpm outdatedpackage.jsondependency managementnode.jsnpmmajor versionnpm-check-updates

Lab evidence

What I found running this

Hands-on on ShopperCove box 5 Oct 2026 ~23:47-23:52 IST (8 vCPU Intel Xeon / 15 GB shared Linux, Node 20.19.2, npm 9.2.0). Fixture: /workspace/bench-ncu/ with axios@1.6.0 eslint@8.57.0 lodash@4.17.21 prettier@3.2.5 react@18.2.0 typescript@5.4.5 vite@5.2.0 + npm-check-updates@23.1.0. 1 warmup + 7 interleaved rounds. Medians: ncu 863 ms, npm outdated 783 ms (exit 1 when outdated is normal). ncu table: 3 minors + 4 majors; for majors npm Wanted=18.3.1/5.4.21/5.9.3/8.57.1 while Latest matched ncu (19.3.0/8.3.2/7.0.2/10.12.0). ncu --format json invalid on 23.1. Raw: /workspace/bench-ncu/res-ncu.json. Not tested: ncu -u writes, workspaces, pnpm/Yarn adapters, interactive filters, Renovate/Dependabot, Windows/macOS. No affiliate.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 68

    pnpm vs npm vs Bun: Which Installs Fastest? 14s, 3.1s, 1.5s

    npm 12.2.0 vs pnpm 12.9.1 vs Bun 1.4.2 on one 24-dependency React + Vite app: from scratch 14.2 s / 3.1 s / 1.5 s; lockfile + warm cache 2.9 s / 0.28 s / 0.27 s; lockfile + empty cache 3.9 s / 2.3 s / 0.45 s. Disk, lockfile size and the pnpm phantom-dependency catch.

    5 Oct 2026

  • Plate 96

    syncpack vs npm-check: Should You Switch? 491ms vs 1.5s

    syncpack 15.3.3 lint vs npm-check 6.0.1 on a 12-package npm workspaces fixture: syncpack median 491 ms offline with 21 version mismatches; npm-check --skip-unused median 1.54 s at root (registry).

    5 Oct 2026

  • Plate 73

    volta vs fnm: Should You Switch? 14ms vs 17ms

    volta 2.0.2 vs fnm 1.39.0 switching Node 20.19.2 ↔ 22.14.0: session A-then-B median 13.9 ms vs 17.0 ms; steady node -v 7.4 ms vs 6.4 ms (direct 4.7 ms).

    5 Oct 2026

On this page

  1. What I tested
  2. What does ncu show that npm outdated does not?
  3. Is ncu faster than npm outdated?
  4. Should you add ncu to the workflow?
  5. Sources
  6. Related
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove