
Security News
The Changelog Podcast: Practical Steps to Stay Safe on npm
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.
bin-links is a standalone library that links
binaries and man pages for JavaScript packages
$ npm install bin-links
const binLinks = require('bin-links')
const readPackageJson = require('read-package-json-fast')
binLinks({
path: '/path/to/node_modules/some-package',
pkg: readPackageJson('/path/to/node_modules/some-package/package.json'),
// true if it's a global install, false for local. default: false
global: true,
// true if it's the top level package being installed, false otherwise
top: true,
// true if you'd like to recklessly overwrite files.
force: true,
})
bin property of pkg to the
node_modules/.bin directory of the installing environment. (Or
${prefix}/bin for top level global packages on unix, and ${prefix}
for top level global packages on Windows.)man property of pkg to the share/man
directory. (This is only done for top-level global packages on Unix
systems.)The npm team enthusiastically welcomes contributions and project participation! There's a bunch of things you can do if you want to contribute! The Contributor Guide has all the information you need for everything from reporting bugs to contributing entire new features. Please don't hesitate to jump in if you'd like to, or even ask us questions if something isn't clear.
> binLinks({path, pkg, force, global, top})Returns a Promise that resolves when the requisite things have been linked.
> binLinks.getPaths({path, pkg, global, top })Returns an array of all the paths of links and shims that might be created (assuming that they exist!) for the package at the specified path.
Does not touch the filesystem.
> binLinks.checkBins({path, pkg, global, top, force })Checks if there are any conflicting bins which will prevent the linking of bins for the given package. Returns a Promise that resolves with no value if the way is clear, and rejects if there's something in the way.
Always returns successfully if global or top are false, or if force
is true, or if the pkg object does not contain any bins to link.
Note that changes to the file system may still cause the binLinks
method to fail even if this method succeeds. Does not check for
conflicting man links.
Reads from the filesystem but does not make any changes.
binLinks({path, pkg, force, global, top}).then(() => console.log('bins linked!'))
6.0.0 (2025-10-23)
bin-links now supports node ^20.17.0 || >=22.9.0efcd20a #155 write-file-atomic@7.0.0420e37e #155 read-cmd-shim@6.0.07c3e533 #155 npm-normalize-package-bin@5.0.0cd743b9 #155 proc-log@6.0.090efc68 #155 cmd-shim@8.0.0The cmd-shim package is similar to bin-links in that it creates shim scripts for node modules to be used as command-line tools. Unlike bin-links, cmd-shim is focused on creating shims compatible with Windows as well as Unix systems.
npm-link is a package that provides functionality to symlink a package folder during development. While it serves a different purpose from bin-links, which links binaries, npm-link is used to link the entire package for development purposes.
FAQs
JavaScript package binary linker
The npm package bin-links receives a total of 3,456,008 weekly downloads. As such, bin-links popularity was classified as popular.
We found that bin-links demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.

Security News
Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood.

Security News
Ruby's creator Matz assumes control of RubyGems and Bundler repositories while former maintainers agree to step back and transfer all rights to end the dispute.