
Security News
How Enterprise Security Is Adapting to AI-Accelerated Threats
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.
typed-install
Advanced tools
You're writing Typescript and it's time to install your favorite node module. Has this ever happened to you?
% npm i my-module @types/my-module
npm ERR! code E404
npm ERR! 404 Not Found: @types/my-module@latest
npm ERR! A complete log of this run can be found in:
npm ERR! /Users/user/.npm/_logs/2018-03-31T23_41_37_683Z-debug.log
It's hard to know if type declarations are included with the module, shipped separately, or non-existent. Enter typed-install.
Install from npm using your favorite package manager.
% npm i -g typed-install
Run it with the typedi command, passing any number space-separated package names (this should be very familiar).
% typedi heroku-config lodash striptags
✔ Installing Packages
✔ Checking for @types
✔ Installing Available Types
The following packages were fully installed:
* lodash
* striptags
The following packages were installed, but lack types:
* heroku-config
By default, typedi guesses your preferred package manager (based on a lockfile), uses npm if there's no hint, saves packages into dependencies, and @types into devDependencies.. This is configurable with the following flags:
devDependenciesdependenciesnpm, yarn, or pnpm. Specifying one of these overwrites lockfile guessing.^). This overwrites your config files for the tool you're usingUsing --dev and --prod together will probably not do what you expect.
As of the release of v1.0.6, the following packages ship with a stub types file, confusing this utility:
jestThose are always explicitly fetched. If you know of another example (or one of the above is shipping actual types) file an issue and I'll add the exception.
If you have npm@5.2.0 or greater installed, you can run this via npx (more info), a tool to run CLI packages without explicitly installing them. This is great for periodic or one time use.
The previous example becomes:
% npx typed-install heroku-config lodash striptags
Similarly, if you're using yarn@2, you can use yarn dlx (see the docs).
If you're going to invoke this repeatedly or frequently, global installation is recommended.
The code that powers typedi can also be used via the Node.js API.
The main function takes the following options, in order:
An array of npm module names
{})an object with any of the following keys (see above):
Any keys not present default to false.
false)Whether or not to run the fancy spinner. If you're using this in other code, this should probably be false. Also controls whether messages are logged.
const typedi = require('typed-install').default
typedi(['lodash', 'striptags'], { dev: true }).then(() => {
console.log('all done!')
})
FAQs
Install packages and types in one fell swoop.
We found that typed-install demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.

Security News
Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood.