Plate 74
ncu vs npm outdated: 4 Majors Beyond Wanted
npm-check-updates 23.1.0 vs npm outdated on 7 stale deps (axios/eslint/lodash/prettier/react/typescript/vite): ncu proposed 4 majors (React 19, Vite 8, TypeScript 7, ESLint 10) while npm Wanted stayed in-range; wall medians 863 ms vs 783 ms.
Aditya Challa5 min read
I ran npm-check-updates (ncu) 23.1.0 and npm outdated on the same package.json with seven intentionally stale deps: ncu proposed four major bumps (React 18 to 19, Vite 5 to 8, TypeScript 5 to 7, ESLint 8 to 10), while npm's Wanted column stayed inside the current major for those four. Wall-clock medians were close: ncu 863 ms, npm outdated 783 ms.
Short answer: use ncu when you want package.json ranges moved to latest, including breaking majors. Use npm outdated when you only want what a normal npm update can install inside today's ranges. No affiliate links in this post.
What I tested
- Machine: 8 vCPU Intel Xeon / 15 GB RAM Linux cloud box, Node 20.19.2 / npm 9.2.0, tested 5 Oct 2026 (about 23:47 to 23:52 IST). Shared box; seven interleaved rounds per command after one warmup each.
- Fixture:
/workspace/bench-ncu/package.jsonwith axios 1.6.0, eslint 8.57.0, lodash 4.17.21, prettier 3.2.5, react 18.2.0, typescript 5.4.5, vite 5.2.0 (plus ncu itself installed locally). - Commands:
npx npm-check-updates(human table),npm outdated(human table). Separate JSON-oriented runs were timed but not used for the major-count story (ncu --format jsonis invalid on 23.1; use other--formatvalues). - Timing: process wall clock via
performance.now()around a fresh child process. Medians: ncu 863 ms, npm outdated 783 ms (npm exits 1 when anything is outdated; that is normal). - Findings: ncu grouped three minor bumps and four majors. For the four majors, npm Wanted stayed on 18.3.1 / 5.4.21 / 5.9.3 / 8.57.1 while Latest matched ncu's targets (19.3.0 / 8.3.2 / 7.0.2 / 10.12.0).
- One surprise: people treat ncu as "faster outdated," but on this box it was slightly slower. The useful difference was the Wanted-versus-latest view, not the milliseconds.
- Not tested:
ncu -uwriting package.json, monorepo / workspaces mode, pnpm or Yarn adapters, interactive reject filters, CI fail-on-major scripts, Windows/macOS.
What does ncu show that npm outdated does not?
| Package | Locked | npm Wanted | npm Latest / ncu target | Gap |
|---|---|---|---|---|
| react | 18.2.0 | 18.3.1 | 19.3.0 | major only in ncu / Latest |
| vite | 5.2.0 | 5.4.21 | 8.3.2 | major only in ncu / Latest |
| typescript | 5.4.5 | 5.9.3 | 7.0.2 | major only in ncu / Latest |
| eslint | 8.57.0 | 8.57.1 | 10.12.0 | major only in ncu / Latest |
| axios | 1.6.0 | 1.20.0 | 1.20.0 | same minor |
| lodash | 4.17.21 | 4.18.1 | 4.18.1 | same minor |
| prettier | 3.2.5 | 3.9.9 | 3.9.9 | same minor |
npm outdated already prints Latest. What it will not do is treat Latest as the upgrade you get from npm update. Wanted is the ceiling of your current range. ncu's default table is a proposal to rewrite those ranges. That is why teams say "ncu found majors npm hid": Wanted hid them, Latest did not.
If you are deciding whether TypeScript 7 is even worth chasing after ncu lists it, see the TypeScript 7 upgrade post. For keeping versions aligned across packages, see syncpack vs npm-check.
Is ncu faster than npm outdated?
| Command | Median wall clock (7 runs) |
|---|---|
| ncu 23.1.0 | 863 ms |
| npm outdated | 783 ms |
No, not here. The gap is noise next to registry latency. Do not pick ncu for speed.
Should you add ncu to the workflow?
| Situation | My pick |
|---|---|
| Monthly "what majors are we behind on?" review | ncu |
Safe npm update preview inside current ranges | npm outdated |
| CI that fails when Wanted moves | npm outdated --json |
| CI that fails when Latest is a new major | ncu (or compare Latest yourself) |
| You already run syncpack / Renovate for ranges | Optional; ncu is redundant |
Bottom line: on seven stale deps, ncu proposed four majors that npm Wanted never suggested. Who should skip ncu: repos that must not rewrite ranges by hand and already trust Renovate or Dependabot pull requests for majors. For unused-dependency cleanup after upgrades, see knip vs depcheck; for runtime package managers around those installs, see pnpm vs npm vs Bun; for a current Vite major after ncu flags it, see the Vite 8.3.2 post.
How this was made: I pinned seven old deps on the ShopperCove test box, ran interleaved ncu and npm outdated processes, saved the tables and timings to JSON, and checked the write-up against that output with AI drafting help.
Sources
- https://github.com/raineorshine/npm-check-updates
- https://www.npmjs.com/package/npm-check-updates
- https://docs.npmjs.com/cli/v9/commands/npm-outdated
- https://docs.npmjs.com/cli/v9/commands/npm-update
Related
- https://www.shoppercove.com/blog/syncpack-vs-npm-check
- https://www.shoppercove.com/blog/typescript-7-should-you-upgrade
- https://www.shoppercove.com/blog/knip-vs-depcheck
- https://www.shoppercove.com/blog/pnpm-vs-npm-vs-bun
- https://www.shoppercove.com/blog/vite-8-3-2-renderbuilturl-bundled-dev-sourcemaps-october-2026
- https://www.shoppercove.com/blog/oxlint-vs-eslint
- https://www.shoppercove.com/blog/lefthook-vs-husky
- https://www.shoppercove.com/blog/volta-vs-fnm
Lab evidence
What I found running this
Hands-on on ShopperCove box 5 Oct 2026 ~23:47-23:52 IST (8 vCPU Intel Xeon / 15 GB shared Linux, Node 20.19.2, npm 9.2.0). Fixture: /workspace/bench-ncu/ with axios@1.6.0 eslint@8.57.0 lodash@4.17.21 prettier@3.2.5 react@18.2.0 typescript@5.4.5 vite@5.2.0 + npm-check-updates@23.1.0. 1 warmup + 7 interleaved rounds. Medians: ncu 863 ms, npm outdated 783 ms (exit 1 when outdated is normal). ncu table: 3 minors + 4 majors; for majors npm Wanted=18.3.1/5.4.21/5.9.3/8.57.1 while Latest matched ncu (19.3.0/8.3.2/7.0.2/10.12.0). ncu --format json invalid on 23.1. Raw: /workspace/bench-ncu/res-ncu.json. Not tested: ncu -u writes, workspaces, pnpm/Yarn adapters, interactive filters, Renovate/Dependabot, Windows/macOS. No affiliate.
Related links
Plate 68
pnpm vs npm vs Bun: Which Installs Fastest? 14s, 3.1s, 1.5s
npm 12.2.0 vs pnpm 12.9.1 vs Bun 1.4.2 on one 24-dependency React + Vite app: from scratch 14.2 s / 3.1 s / 1.5 s; lockfile + warm cache 2.9 s / 0.28 s / 0.27 s; lockfile + empty cache 3.9 s / 2.3 s / 0.45 s. Disk, lockfile size and the pnpm phantom-dependency catch.
5 Oct 2026
Plate 96
syncpack vs npm-check: Should You Switch? 491ms vs 1.5s
syncpack 15.3.3 lint vs npm-check 6.0.1 on a 12-package npm workspaces fixture: syncpack median 491 ms offline with 21 version mismatches; npm-check --skip-unused median 1.54 s at root (registry).
5 Oct 2026
Plate 73
volta vs fnm: Should You Switch? 14ms vs 17ms
volta 2.0.2 vs fnm 1.39.0 switching Node 20.19.2 ↔ 22.14.0: session A-then-B median 13.9 ms vs 17.0 ms; steady node -v 7.4 ms vs 6.4 ms (direct 4.7 ms).
5 Oct 2026