Skip to content

[BUG] npm publish results in Cannot find module 'sigstore' #9722

Description

@james-pre

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

This is not just a request to bump a dependency for a CVE

  • This is not solely a request to bump a dependency for a CVE

Current Behavior

This occurred in a CI release workflow run:

Run npm publish --access=public --provenance
npm error code MODULE_NOT_FOUND
npm error Cannot find module 'sigstore'
npm error Require stack:
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/node_modules/libnpmpublish/lib/provenance.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/node_modules/libnpmpublish/lib/publish.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/node_modules/libnpmpublish/lib/index.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/lib/commands/publish.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/lib/npm.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/lib/cli/entry.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/lib/cli.js
npm error - /opt/hostedtoolcache/node/26.4.0/x64/lib/node_modules/npm/bin/npm-cli.js
npm error A complete log of this run can be found in: /home/runner/.npm/_logs/2026-07-05T20_19_26_876Z-debug-0.log

source

Expected Behavior

This should work correctly

Steps To Reproduce

  1. Set up a CI workflow to publish
  2. Run npm publish --access=public --provenance in the workflow
  3. It fails

Environment

  • npm: 12.0.0-pre.2
  • Node.js: 24.6.0
  • OS Name: ubuntu-latest
  • System Model Name: unknown
  • npm config: unavailable (its on a GitHub actions runner), though install-strategy=linked is set in .npmrc

Activity

  1. jleclanche commented on Jul 9, 2026

    @jleclanche

    We hit the same failure on npm 12.0.0 stable (released 2026-07-08), publishing with OIDC trusted publishing + NPM_CONFIG_PROVENANCE=true on GitHub-hosted runners. Same MODULE_NOT_FOUND for sigstore from libnpmpublish/lib/provenance.js.

    Root cause appears to be a release packaging bug, not an intended change:

    • libnpmpublish@12.0.0 still declares "sigstore": "^5.0.0" in its dependencies, and its lib/provenance.js still requires it.
    • But the published npm-12.0.0.tgz does not contain the module — tar tzf npm-12.0.0.tgz | grep -c '^package/node_modules/sigstore/' returns 0, while npm-11.18.0.tgz bundles it (5 entries). Other sigstore packages (@sigstore/tuf etc.) made it into the 12.0.0 tarball; sigstore itself was dropped somewhere in the bundling step.
    • Neither the npm 12.0.0 nor the libnpmpublish 12.0.0 release notes mention removing provenance support.

    So any npm publish with provenance enabled (explicit --provenance, NPM_CONFIG_PROVENANCE=true, or provenance via trusted publishing) crashes on npm 12.0.0.

    Workaround until a patched 12.x ships: pin the 11.x line in CI — npm install -g npm@11 — which restores a working bundled sigstore.

  2. zdm commented on Jul 9, 2026

    @zdm

    It also failed when just make simple publish: npm publish.
    sigstore module is missed.

  3. added a commit that references this issue on Jul 9, 2026
  4. 71 remaining items

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingNeeds Triageneeds review for next steps

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions