Skip to content

Remove dependency on Chocolatey #51905

Description

@cinderblock

What is the problem this feature will solve?

Windows users are concerned by the check box in the installer (#30242) - why not remove the external dependency?

Chocolatey is an independent, open core (with proprietary extensions), package manager for Windows that recreates existing functionality included in all current versions of Windows. Chocolatey has its own set of problems, mostly stemming from the independent partially closed source for profit nature of the project.

What is the feature you are proposing to solve the problem?

winget is an open source package manager from Microsoft and is installed by default on modern versions of Windows. It has all the packages that Chocolatey wants to install.

This is equivalent to the checkbox, with newer package versions, and without Chocolatey:

winget install -e --id Python.Python.3.12
winget install -e --id Microsoft.VisualStudio.2022.Community --override "--passive --wait --add Microsoft.VisualStudio.Workload.VCTools"

What alternatives have you considered?

WiX Toolset, which is already in use, might have all the capabilities necessary to install these optional dependencies without using any PowerShell scripts.

Additional Resources

Activity

  1. aduh95 commented on Mar 2, 2024

    @aduh95
    Contributor

    The issue is that the Windows installer suggests to install Chocolatey, correct? If someone sends a PR to use a different package manager, it seems likely to me that it'd be accepted.

  2. cinderblock commented on Mar 5, 2024

    @cinderblock
    Author

    That seems correct to me. Most other installers I've used don't install some other tool to install more optional tools.

    I guess there isn't really a reason to depend on winget either. In my experience, usually installers with optional features give a more detailed drop down that allows users to opt in to each set of optional features directly - no external tooling necessary.

    I'm thinking something like this:
    image

    Looking at the code, there are only a couple references to "chocolatey". It should be easy enough to replace/update install_tools.bat to use winget - but maybe something higher level in the installer configuration would look better - maybe a user wants to use some existing python binary and to use gcc instead of VCTools (getting node-gyp to support that flexibility is outside the scope of this change) or different versions of Visual Studio.

  3. Daverd-GM commented on Jul 12, 2024

    @Daverd-GM
    Contributor

    don't know if this is the right place but also the chocolatey script for installing the build tools is outdated for node 22 because it still installs the vs2019 tools

  4. cinderblock commented on Jul 23, 2024

    @cinderblock
    Author

    I'm wondering if the best solution for this is to use WiX Toolset's features directly. I suspect it would be possible for it to download and install the necessary tools (with the same check box) without the PowerShell script.

    However, I'm not very familiar with the WiX Toolset and am not sure quite where to start, or even how to test it...

    Does anyone have a opinions on keeping the PowerShell script and changing it to use winget vs using WiX Toolset to directly install the optional dependencies? Can someone speak to if WiX Toolset supports installing optional dependencies like this?

    Edit: StackOverflow seems to suggest using a "Burn".

  5. nemchik commented on Jul 23, 2024

    @nemchik

    No idea about WiX, but I like the idea of winget. I believe Win10 does not include winget by default, so it would need to be installed. I think (not positive) Win11 does include winget out of the box.

  6. avivkeller commented on Sep 13, 2024

    @avivkeller
    Member

    Windows 11 does include winget by default, AFAIK

  7. avivkeller commented on Sep 13, 2024

    @avivkeller
    Member

    Also, FWIW i think the following will work:

    $progressPreference = 'silentlyContinue'
    
    @REM # Check if winget is available
    if (-not (Get-Command winget -ErrorAction SilentlyContinue)) {
        Write-Information "Winget not found. Downloading WinGet and its dependencies..."
        
        # Download and install WinGet and its dependencies
        Invoke-WebRequest -Uri https://aka.ms/getwinget -OutFile Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle
        Invoke-WebRequest -Uri https://aka.ms/Microsoft.VCLibs.x64.14.00.Desktop.appx -OutFile Microsoft.VCLibs.x64.14.00.Desktop.appx
        Invoke-WebRequest -Uri https://github.com/microsoft/microsoft-ui-xaml/releases/download/v2.8.6/Microsoft.UI.Xaml.2.8.x64.appx -OutFile Microsoft.UI.Xaml.2.8.x64.appx
        
        Add-AppxPackage Microsoft.VCLibs.x64.14.00.Desktop.appx
        Add-AppxPackage Microsoft.UI.Xaml.2.8.x64.appx
        Add-AppxPackage Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle
    }
    
    @REM # Proceed with winget commands if winget is available
    winget install Microsoft.VisualStudio.2022.BuildTools --override "--passive --wait --add Microsoft.VisualStudio.Workload.VCTools;includeRecommended"
    winget install Git.Git
    winget install Python.Python.3.12
    winget install NASM.NASM
    

    I haven't tested it tho.

    Diff
    diff --git a/BUILDING.md b/BUILDING.md
    index d702bd0948..26f8a36316 100644
    --- a/BUILDING.md
    +++ b/BUILDING.md
    @@ -666,15 +666,13 @@ NOTE: Currently we only support compiling with Clang that comes from Visual Stud
     
     A [Boxstarter](https://boxstarter.org/) script can be used for easy setup of
     Windows systems with all the required prerequisites for Node.js development.
    -This script will install the following [Chocolatey](https://chocolatey.org/)
    +This script will install the following [WinGet](https://learn.microsoft.com/en-us/windows/package-manager/winget/)
     packages:
     
    -* [Git for Windows](https://chocolatey.org/packages/git) with the `git` and
    -  Unix tools added to the `PATH`
    -* [Python 3.x](https://chocolatey.org/packages/python)
    -* [Visual Studio 2022 Build Tools](https://chocolatey.org/packages/visualstudio2022buildtools)
    -  with [Visual C++ workload](https://chocolatey.org/packages/visualstudio2022-workload-vctools)
    -* [NetWide Assembler](https://chocolatey.org/packages/nasm)
    +* Git for Windows
    +* Python 3.12
    +* Visual Studio 2022 Build Tools with the Visual C++ workload
    +* NetWide Assembler
     
     To install Node.js prerequisites using
     [Boxstarter WebLauncher](https://boxstarter.org/weblauncher), open
    diff --git a/tools/msvs/install_tools/install_tools.bat b/tools/msvs/install_tools/install_tools.bat
    index 18f92a9810..ebabffde79 100644
    --- a/tools/msvs/install_tools/install_tools.bat
    +++ b/tools/msvs/install_tools/install_tools.bat
    @@ -10,8 +10,8 @@ echo Tools for Node.js Native Modules Installation Script
     echo ====================================================
     echo.
     echo This script will install Python and the Visual Studio Build Tools, necessary
    -echo to compile Node.js native modules. Note that Chocolatey and required Windows
    -echo updates will also be installed.
    +echo to compile Node.js native modules. Note that required Windows updates will
    +echo also be installed.
     echo.
     echo This will require about 3 GiB of free disk space, plus any space necessary to
     echo install Windows updates. This will take a while to run.
    @@ -28,28 +28,24 @@ pause
     
     cls
     
    -REM Adapted from https://github.com/Microsoft/windows-dev-box-setup-scripts/blob/79bbe5bdc4867088b3e074f9610932f8e4e192c2/README.md#legal
    -echo Using this script downloads third party software
    -echo ------------------------------------------------
    -echo This script will direct to Chocolatey to install packages. By using
    -echo Chocolatey to install a package, you are accepting the license for the
    -echo application, executable(s), or other artifacts delivered to your machine as a
    -echo result of a Chocolatey install. This acceptance occurs whether you know the
    -echo license terms or not. Read and understand the license terms of the packages
    -echo being installed and their dependencies prior to installation:
    -echo - https://chocolatey.org/packages/chocolatey
    -echo - https://chocolatey.org/packages/python
    -echo - https://chocolatey.org/packages/visualstudio2019-workload-vctools
    -echo.
    -echo This script is provided AS-IS without any warranties of any kind
    -echo ----------------------------------------------------------------
    -echo Chocolatey has implemented security safeguards in their process to help
    -echo protect the community from malicious or pirated software, but any use of this
    -echo script is at your own risk. Please read the Chocolatey's legal terms of use
    -echo as well as how the community repository for Chocolatey.org is maintained.
    -echo.
    -pause
    +$progressPreference = 'silentlyContinue'
     
    -cls
    +@REM # Check if winget is available
    +if (-not (Get-Command winget -ErrorAction SilentlyContinue)) {
    +    Write-Information "Winget not found. Downloading WinGet and its dependencies..."
    +    
    +    # Download and install WinGet and its dependencies
    +    Invoke-WebRequest -Uri https://aka.ms/getwinget -OutFile Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle
    +    Invoke-WebRequest -Uri https://aka.ms/Microsoft.VCLibs.x64.14.00.Desktop.appx -OutFile Microsoft.VCLibs.x64.14.00.Desktop.appx
    +    Invoke-WebRequest -Uri https://github.com/microsoft/microsoft-ui-xaml/releases/download/v2.8.6/Microsoft.UI.Xaml.2.8.x64.appx -OutFile Microsoft.UI.Xaml.2.8.x64.appx
    +    
    +    Add-AppxPackage Microsoft.VCLibs.x64.14.00.Desktop.appx
    +    Add-AppxPackage Microsoft.UI.Xaml.2.8.x64.appx
    +    Add-AppxPackage Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle
    +}
     
    -"%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -InputFormat None -ExecutionPolicy Bypass -Command Start-Process '%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe' -ArgumentList '-NoProfile -InputFormat None -ExecutionPolicy Bypass -Command [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; iex ((New-Object System.Net.WebClient).DownloadString(''https://chocolatey.org/install.ps1'')); choco upgrade -y python visualstudio2019-workload-vctools; Read-Host ''Type ENTER to exit'' ' -Verb RunAs
    +@REM # Proceed with winget commands if winget is available
    +winget install Microsoft.VisualStudio.2022.BuildTools --override "--passive --wait --add Microsoft.VisualStudio.Workload.VCTools;includeRecommended"
    +winget install Git.Git
    +winget install Python.Python.3.12
    +winget install NASM.NASM
    diff --git a/tools/msvs/msi/nodemsi/i18n/en-us.wxl b/tools/msvs/msi/nodemsi/i18n/en-us.wxl
    index 5074d5a431..b3a68aabf6 100644
    --- a/tools/msvs/msi/nodemsi/i18n/en-us.wxl
    +++ b/tools/msvs/msi/nodemsi/i18n/en-us.wxl
    @@ -12,7 +12,7 @@
         <String Id="NativeToolsDlgDescription" Value="Optionally install the tools necessary to compile native modules."/>
         <String Id="NativeToolsDlgBannerBitmap" Value="WixUI_Bmp_Banner"/>
         <String Id="NativeToolsDlgIntro" Value="Some npm modules need to be compiled from C/C++ when installing. If you want to be able to install such modules, some tools (Python and Visual Studio Build Tools) need to be installed."/>
    -    <String Id="NativeToolsDlgInstallCheckbox" Value="Automatically install the necessary tools. Note that this will also install Chocolatey. The script will pop-up in a new window after the installation completes."/>
    +    <String Id="NativeToolsDlgInstallCheckbox" Value="Automatically install the necessary tools. Note that this will also install WinGet if it is not already installed."/>
         <String Id="NativeToolsDlgManualDetails" Value="Alternatively, follow the instructions at &lt;a href=&quot;https://github.com/nodejs/node-gyp#on-windows&quot;&gt;https://github.com/nodejs/node-gyp#on-windows&lt;/a&gt; to install the dependencies yourself."/>
     
         <!-- References like [ProductName] or $(var.ProductName) don't seem to work in Title attributes -->
  8. cinderblock commented on Sep 16, 2024

    @cinderblock
    Author

    While the comments reference NASM, the choco update ... doesn't reference NASM... (nor git). We shouldn't be adding other dependencies, imho.

    @redyetidev Why the --passive and --wait?

    If you want to try it, push a PR (or fork and push to your own repo). The GitHub Actions will build a whole installer with the new script and you can test it.

  9. avivkeller commented on Sep 16, 2024

    @avivkeller
    Member

    I'd wait until winget comes standard with all builds

  10. cinderblock commented on Sep 16, 2024

    @cinderblock
    Author

    WinGet is (apparently) installed by default on recent versions of Windows 10... What more would you wait for?

    I'm personally more partial to using WiX directly as that seems to align more with Windows standards that I'm familiar with.

  11. avivkeller commented on Sep 16, 2024

    @avivkeller
    Member

    Well, that's just my opinion

    @nodejs/platform-windows WDYT

  12. github-actions commented on Mar 16, 2025

    @github-actions
    Contributor

    There has been no activity on this feature request for 5 months. To help maintain relevant open issues, please add the never-stale Issues and PRs exempt from automated stale handling. label or close this issue if it should be closed. If not, the issue will be automatically closed 6 months after the last non-automated comment.
    For more information on how the project manages feature requests, please consult the feature request management document.

  13. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Mar 16, 2025
  14. cinderblock commented on Mar 17, 2025

    @cinderblock
    Author
  15. removed
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Mar 18, 2025
  16. added
    never-staleIssues and PRs exempt from automated stale handling.
    on Mar 18, 2025
  17. saper commented on Apr 10, 2025

    @saper

    While the comments reference NASM, the choco update ... doesn't reference NASM... (nor git). We shouldn't be adding other dependencies, imho.

    @redyetidev Why the --passive and --wait?

    If you want to try it, push a PR (or fork and push to your own repo). The GitHub Actions will build a whole installer with the new script and you can test it.

    I just tried it - I am not sure if --passive works at all, as the command pops up a big vs_setup_bootstrap.exe popup. Without --wait winget will exit after a while once the vs_setup is running.

  18. cinderblock commented on Apr 11, 2025

    @cinderblock
    Author
  19. saper commented on Apr 14, 2025

    @saper

    I think docs for WinGet install are for winget itself, the --override option passes --passive and --wait to the Visual Studio setup bootstrapper, which does it ... differently.

    I can confirm that --passive pops up a GUI dialog that displays progress (can be useful as it takes quite a long time to get and install everything). --wait causes the bootstrapper to wait until the whole setup is complete to return an exit code and not return early to the invoking process.

    https://learn.microsoft.com/en-us/visualstudio/install/command-line-parameter-examples?view=vs-2022#using---wait

  20. cinderblock commented on Apr 15, 2025

    @cinderblock
    Author

    Ah. Thank you. I'd missed that.

    Trying the command myself, I'm getting errors when I run it again. Is this not idempotent?

  21. saper commented on Apr 15, 2025

    @saper

    You need to make sure no Visual Studio bootstrapper or setup running while re-running this. But I am guessing here.

    Ideally, we should get a free software toolchain to build this thing :(

  22. cinderblock commented on Apr 16, 2025

    @cinderblock
    Author

    Curious... My two Windows 11 systems are behaving slightly differently, but both give a non-zero exit code.

    At home, it doesn't even launch the Visual Studio Installer gui.

    Found an existing package already installed. Trying to upgrade the installed package...
    No available upgrade found.
    No newer package versions are available from the configured sources.
    
    [process exited with code 2316632107 (0x8a15002b)]
    

    At work, it downloads a binary, launches a gui that quickly gets to 100%, and closes but then shows a basic error message in the terminal.

    Found an existing package already installed. Trying to upgrade the installed package...
    Found Visual Studio Community 2022 [Microsoft.VisualStudio.2022.Community] Version 17.13.6
    This application is licensed to you by its owner.
    Microsoft is not responsible for, nor does it grant any licenses to, third-party packages.
    Downloading https://download.visualstudio.microsoft.com/download/pr/8fada5c7-8417-4239-acc3-bd499af09222/3abfebadd684b60fc63fe91eb7faf5a56f387165af325b6441ddacfe0cee9d6a/vs_Community.exe
      ██████████████████████████████  4.24 MB / 4.24 MB
    Successfully verified installer hash
    Starting package install...
    The installer will request to run as administrator. Expect a prompt.
    

    Image

    Installer failed with exit code: 1
    
    [process exited with code 2316632070 (0x8a150006)]
    

    I have dreams of replacing node-gyp as the defacto native build tool for Node.js. Still confused how we ended up with a Python based build tool as the apparently recommended option for Node.js.

  23. bnoordhuis commented on Apr 17, 2025

    @bnoordhuis
    Member

    Still confused how we ended up with a Python based build tool as the apparently recommended option for Node.js

    Because node-gyp is a wrapper around gyp, which is also the build tool for node.js itself, and that's a python project. Various JS ports exist but never got much traction.

  24. tekowalsky commented on Jul 4, 2026

    @tekowalsky

    For awareness, this is installing the "free" version of Chocolatey which uses the "community" repository.

    The Chocolatey Software 'Security' page strongly recommends organizations (and security conscious individuals) should not use the "community" repository.

    "Most organizations using Chocolatey do NOT use the community repository, and Chocolatey Software using the community repository either for organizational deployments for a variety of reasons."

    "When you use Chocolatey in an organizational sense, do so in a manner that requires no internet access. Chocolatey doesn’t require internet access at all."

    "t goes without stating that if you are a business and you are using Chocolatey, you should think long and hard before trusting an external source you have no control over (community.chocolatey.org packages, in addition to all of the binaries that download from official distribution channels over the internet)."

    "Organizations typically do not use the community repository anyway and only use Chocolatey in a completely secure manner."

  25. added
    windowsIssues and PRs related to the Windows platform.
    on Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature requestIssues requesting new Node.js features.never-staleIssues and PRs exempt from automated stale handling.windowsIssues and PRs related to the Windows platform.

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions