Repository navigation
[BUG] npm publish results in Cannot find module 'sigstore' #9722
Copy link
Copy link
Closed
Labels
Bugthing that needs fixingthing that needs fixingNeeds Triageneeds review for next stepsneeds review for next steps
Description
Activity
- addedBugthing that needs fixingthing that needs fixingNeeds Triageneeds review for next stepsneeds review for next steps
on Jul 5, 2026 - added a commit that references this issue
on Jul 8, 2026 - added a commit that references this issue
on Jul 8, 2026 - added a commit that references this issue
on Jul 9, 2026 - added a commit that references this issue
on Jul 9, 2026 We hit the same failure on npm 12.0.0 stable (released 2026-07-08), publishing with OIDC trusted publishing +
NPM_CONFIG_PROVENANCE=trueon GitHub-hosted runners. SameMODULE_NOT_FOUNDforsigstorefromlibnpmpublish/lib/provenance.js.Root cause appears to be a release packaging bug, not an intended change:
libnpmpublish@12.0.0still declares"sigstore": "^5.0.0"in itsdependencies, and itslib/provenance.jsstillrequires it.- But the published
npm-12.0.0.tgzdoes not contain the module —tar tzf npm-12.0.0.tgz | grep -c '^package/node_modules/sigstore/'returns0, whilenpm-11.18.0.tgzbundles it (5 entries). Other sigstore packages (@sigstore/tufetc.) made it into the 12.0.0 tarball;sigstoreitself was dropped somewhere in the bundling step. - Neither the npm 12.0.0 nor the libnpmpublish 12.0.0 release notes mention removing provenance support.
So any
npm publishwith provenance enabled (explicit--provenance,NPM_CONFIG_PROVENANCE=true, or provenance via trusted publishing) crashes on npm 12.0.0.Workaround until a patched 12.x ships: pin the 11.x line in CI —
npm install -g npm@11— which restores a working bundledsigstore.Reacted by Grzegorz Olędzki, Fuma Nama, Dmytro Z., Florian Wendelborn, Shiv, Elizabeth Craig and Tiago @ Siebly.io- added a commit that references this issue
on Jul 9, 2026 - added a commit that references this issue
on Jul 9, 2026 - added a commit that references this issue
on Jul 9, 2026 It also failed when just make simple publish:
npm publish.
sigstoremodule is missed.Reacted by Thomas Witt and Martin Pedersen- added a commit that references this issue
on Jul 9, 2026 - added a commit that references this issue
on Jul 9, 2026 - added a commit that references this issue
on Jul 9, 2026 - added a commit that references this issue
on Jul 9, 2026 71 remaining items
- added 2 commits that reference this issue
on Jul 29, 2026 - added 6 commits that reference this issue
on Sep 1, 2026 - added a commit that references this issue
on Sep 24, 2026 - added a commit that references this issue
on Oct 5, 2026 - added a commit that references this issue
on Oct 8, 2026
Metadata
Metadata
Assignees
Labels
Bugthing that needs fixingthing that needs fixingNeeds Triageneeds review for next stepsneeds review for next steps
Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
Current Behavior
This occurred in a CI release workflow run:
source
Expected Behavior
This should work correctly
Steps To Reproduce
npm publish --access=public --provenancein the workflowEnvironment
install-strategy=linkedis set in.npmrc