Skip to content

npm cli built into NodeJS 16.18.0 (npm cli 8.19.2) broken with git+ssh urls #44992

Description

@breisig

Version

v16.18.0

Platform

Rocky Linux 9

Subsystem

No response

What steps will reproduce the bug?

When compiling from source NodeJS 16.18.0, It installs npm cli version 8.19.2. We have a private url in our package.json file

"nodejs-elastic": "git+ssh://git@git.example.com:components/ourpackage.git#v2.0.1",

and whenever we run 'npm install', It always shows an error.

npm ERR! code ERR_INVALID_URL
npm ERR! Invalid URL

npm ERR! A complete log of this run can be found in:
npm ERR!     /home/testuser/.npm/_logs/2022-10-13T15_53_58_387Z-debug-0.log

However, If I manually downgrade to the NPM CLI version included in NodeJS 16.17.1 (npm cli version:8.15.0), it runs without issue.

How often does it reproduce? Is there a required condition?

all the time with the new version

What is the expected behavior?

Installs normally without issue.

What do you see instead?

errors

Additional information

No response

Activity

  1. changed the title [-]npm cli built into NodeJS 16.18.0 (npm cli 8.19.1) broken with git+ssh urls[/-] [+]npm cli built into NodeJS 16.18.0 (npm cli 8.19.2) broken with git+ssh urls[/+] on Oct 13, 2022
  2. richardlau commented on Oct 13, 2022

    @richardlau
    Member

    cc @nodejs/npm

  3. Trott commented on Oct 13, 2022

    @Trott
    Member

    I'm unable to replicate this with the same Node.js and npm versions on macOS.

    Does it work from the command-line without a package.json entry, such as with this command?

    npm install 'git+ssh://git@github.com/Trott/slug.git#v2.0.0'
    
    $ node -v
    v16.18.0
    $ npm -v
    8.19.2
    $ npm install 'git+ssh://git@github.com/Trott/slug.git#v8.2.2'
    
    added 1 package, and audited 2 packages in 3s
    
    found 0 vulnerabilities
    $ 
  4. breisig commented on Oct 13, 2022

    @breisig
    Author

    @Trott We are pointing to our own internal git repository.

  5. richardlau commented on Oct 13, 2022

    @richardlau
    Member
  6. breisig commented on Oct 17, 2022

    @breisig
    Author

    @Trott I can install your repo but not our internal repo. Again, this is the issues with npm cli 8.19.2.

    test@localdev ~$ node -v
    v16.18.0
    test@localdev ~$ npm -v
    8.19.2
    test@localdev ~$
    
    npm install 'git+ssh://git@github.com/Trott/slug.git#v2.0.0'
    
    test@localdev ~$ npm install 'git+ssh://git@github.com/Trott/slug.git#v2.0.0'
    
    added 1 package, changed 1 package, and audited 3 packages in 3s
    
    found 0 vulnerabilities
    

    However when I try to manually install our internal git repository

    npm install 'git+ssh://git@git.example.com:components/ourpackage.git#v2.0.1'
    npm ERR! code ERR_INVALID_URL
    npm ERR! Invalid URL
    
    npm ERR! A complete log of this run can be found in:
    npm ERR!     /home/test/.npm/_logs/2022-10-17T23_05_26_929Z-debug-0.log
    

    Again, this wasn't an issue with NodeJS 16.17.1 which includes npm cli version:8.15.0. If I downgrade to NPM cli 8.15.0, it works. (see below)

    test@localdev ~# sudo npm install -g npm@8.15.0
    
    removed 10 packages, changed 54 packages, and audited 202 packages in 1s
    
    11 packages are looking for funding
      run `npm fund` for details
    
    found 0 vulnerabilities
    
    test@localdev ~$ npm --version
    8.15.0
    test@localdev ~$ npm install 'git+ssh://git@git.example.com:components/ourpackage.git#v2.0.1'
    
    added 1 package, and audited 4 packages in 2m
    
    found 0 vulnerabilities
    

    This is a SERIOUS issues from npm cli that breaks the current version included in the latest NodeJS versions (stable+latest)

  7. vizdatom commented on Oct 20, 2022

    @vizdatom

    Hi, I have the same issue with node 16.18.0 (npm 8.19.2) on Windows 10. However, node 16.17.1 works fine.

  8. frank-dspeed commented on Oct 25, 2022

    @frank-dspeed
    Contributor

    hmmm i did answer that just in the repo but i do not find it anyway the workaround is:

    npm switched to use new URL() that parser does not accept double : so you can simply change

    : to /
    

    example workaround

    // will not work note it contains 2x the : character
    npm i git+ssh://git@git.example.com:compon....................
    // will work see the part before comp there we changed : to /
    npm i git+ssh://git@git.example.com/compon....................
    

    greetings. and yes this will stay working you can apply that to all your files.

    Linking Related issues there do come up a lot

  9. lukekarrys commented on Oct 27, 2022

    @lukekarrys
    Member

    I have an open pull request that will fix this issue here: npm/cli#5758

    It should land in the next couple days and be released as part of the v9 release line next Wednesday. I also have a plan to backport this fix to v8 (npm/cli#5761), due to the serious nature of the bug.

  10. lukekarrys commented on Nov 1, 2022

    @lukekarrys
    Member

    This will land in the next release of npm@9 and npm@8.19.3

  11. wraithgar commented on Nov 1, 2022

    @wraithgar
    Contributor

    GitHub auto-closed this cause luke had linked his PRs to this issue. Tomorrow's CLI release will include the fixes for this.

  12. added a commit that references this issue on Feb 6, 2023
  13. added a commit that references this issue on Feb 10, 2023
  14. added a commit that references this issue on Feb 24, 2023
  15. added a commit that references this issue on Mar 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions