Read the first error, not the last line. On an old project, npm install usually fails for one of four reasons: your Node version is much newer than the project expects, the lockfile and package.json disagree, a package has to compile native code and the build tools aren't installed, or a package has been removed or renamed. Install the Node version the project was built with, do a clean install, and work forward from there.
What's the problem
You clone the project or open it after a long gap, run npm install, and get a wall of red: "npm ERR! code 1", "gyp ERR!", "ENOENT", "unable to get local issuer certificate". Nothing has changed in the code. The world around it has.
Why it happens
- Node moved on. The project was written for a Node version that's now years old. Node 20 and everything before it are end of life. Packages written for old Node often won't build on new Node, and vice versa.
- The lockfile and package.json disagree. A clean install with
npm cistops with an error rather than guessing. - Native packages need compiling. Some packages (image processing, encryption, older Sass) compile code during install. That needs Python and C++ build tools, and old versions of those packages may not compile on new Node at all.
- Packages disappear or move. Old versions get deprecated or removed, and some packages get renamed or abandoned.
- Your network is in the way. "Unable to get local issuer certificate" usually means a corporate proxy or antivirus is intercepting secure connections.
How to fix it
- Find the Node version the project expects. Look for an
.nvmrcor.node-versionfile, theenginesfield inpackage.json, aDockerfile, or build settings. The age of the last commit is a rough guide too. - Install that version with a version manager (nvm, or nvm-windows on Windows) and switch to it for this project.
- Do a clean install. Delete
node_modulesand runnpm ci. Ifnpm cicomplains the lockfile doesn't match, runnpm installonce and commit the updated lockfile. - For native build errors (gyp, Visual C++, Python), install your platform's build tools, or update that package to a version that ships prebuilt binaries.
- For certificate errors, configure npm to trust your network's certificate. Don't switch off certificate checking.
- Once it installs and runs on the old version, record the version in an
.nvmrcfile, then plan the upgrade to a supported Node release. See the project only runs on an old version of Node.
When to call Preventionlabs
If the right Node version and a clean install get it running, you're through the hardest part. Call us when it's still failing after that, because packages no longer exist, nothing compiles, or each fix exposes another. The first thing a resurrection delivers is an app that builds and starts on maintained dependencies, deployed in your own hosting account.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- Node.js: Node.js Releasesofficial docs
Production applications should only use Active LTS or Maintenance LTS releases.
- Node.js: Node.js Releases: release tableofficial docs
v 20 Iron Apr 17, 2023 Mar 24, 2026 EOL
- npm: npm ciofficial docs
If dependencies in the package lock do not match those in package.json, npm ci will exit with an error, instead of updating the package lock.
- Netlify: Manage build dependencieshosting platform docs
Add a .node-version or .nvmrc file to the site’s base directory in your repository.