Skip to content

fix(arborist): record the linked .store layout in the hidden lockfile - #9630

Merged
owlstronaut merged 1 commit into
npm:latestfrom
manzoorwanijk:fix/linked-hidden-lockfile-store-layout
Jun 24, 2026
Merged

owlstronaut merged 1 commit into
npm:latestfrom
manzoorwanijk:fix/linked-hidden-lockfile-store-layout

Conversation

@manzoorwanijk

@manzoorwanijk manzoorwanijk commented Jun 24, 2026 •

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, the hidden lockfile node_modules/.package-lock.json recorded the hoisted logical layout (node_modules/<pkg>) instead of the actual on-disk .store/symlink layout. The hidden lockfile is meant to cache what loadActual() finds on disk so the actual tree can be validated cheaply, but because it recorded the wrong layout it was rejected on every reload, so it never served as a cache and misrepresented the installed layout.

Why

A linked reify swaps idealTree for the isolated tree, materializes the .store/symlink layout, then swaps the logical tree back before saving. The hidden lockfile was serialized from that logical tree, so it listed packages at their hoisted paths. On the next load, assertNoNewer() walked the real node_modules (the root symlink plus .store/) and could not reconcile it with the hoisted entries, throwing missing from lockfile, so loadActual() always fell back to a full filesystem scan.

How

reify.js serializes the hidden lockfile from the isolated tree, which mirrors the on-disk layout, while package-lock.json still comes from the logical tree. It records every store package directory and symlink, adds an entry for each .store/<key> container directory (these are the fsParents loadVirtual() needs so a store package can resolve its sibling deps), includes the workspace directories, and skips tree-only undeclared-workspace self-links that are never materialized on disk.

assertNoNewer() additionally validates the directories the plain node_modules walk cannot reach under the linked strategy: a store package's deps live as symlinked siblings under .store/<key>/node_modules (and .store is skipped as a dot-dir), and an undeclared workspace is not symlinked into the root node_modules at all. These directories are derived from the lockfile entries. A workspace directory is only walked when it is not the target of a link entry, so the hoisted strategy keeps its existing, stricter validation unchanged — a stale workspace symlink that points at the wrong target still surfaces as a missing entry and rejects the cache.

References

Fixes #9612
Part of #9608

@manzoorwanijk
manzoorwanijk force-pushed the fix/linked-hidden-lockfile-store-layout branch from f6abc1b to 658c010 Compare June 24, 2026 13:29
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 13:33
@manzoorwanijk
manzoorwanijk requested review from a team as code owners June 24, 2026 13:33
@manzoorwanijk
manzoorwanijk force-pushed the fix/linked-hidden-lockfile-store-layout branch from 658c010 to f723efa Compare June 24, 2026 14:36
@owlstronaut
owlstronaut merged commit 6968015 into npm:latest Jun 24, 2026
23 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Backport to release/v11 failed.

This usually means the cherry-pick had conflicts. Please create a manual backport:

git fetch origin release/v11
git checkout -b backport/v11/9630 origin/release/v11
git cherry-pick -x 696801574984ad19ffaa9a7200d7e752920a018d
# resolve any conflicts, then:
git push origin backport/v11/9630
Error details
Command failed: git cherry-pick -x 696801574984ad19ffaa9a7200d7e752920a018d
error: could not apply 696801574... fix(arborist): record the linked .store layout in the hidden lockfile (#9630)
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

@manzoorwanijk
manzoorwanijk deleted the fix/linked-hidden-lockfile-store-layout branch June 24, 2026 17:49
@manzoorwanijk

Copy link
Copy Markdown
Contributor Author

Creating a manual backport for this...

@manzoorwanijk

Copy link
Copy Markdown
Contributor Author

Here you go #9642

owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
… (backport #9630) (#9642)

Backport of #9630 to `release/v11`.

Under `install-strategy=linked`, the hidden lockfile
`node_modules/.package-lock.json` recorded the hoisted logical layout
instead of the on-disk `.store`/symlink layout, so it was rejected on
every reload and never served as the actual-tree cache it is meant to
be.

## How

`reify.js` serializes the hidden lockfile from the isolated tree, which
mirrors the on-disk layout, while `package-lock.json` still comes from
the logical tree. `assertNoNewer()` additionally validates the store
package node_modules and undeclared-workspace subtrees that the plain
`node_modules` walk cannot reach under the linked strategy, gated so the
hoisted strategy keeps its existing, stricter validation.

The original commit's change to `test/arborist/reify-npm-extension.js`
was dropped because the `.npm-extension` feature does not exist on
`release/v11`.

## References

Backport of #9630
Part of #9608
@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
renovate Bot added a commit to gwennlbh/swarpc that referenced this pull request Oct 7, 2026
##### [v11.21.0](npm/cli@v11.20.0...5fd1e17)

##### [v11.20.0](https://github.com/npm/cli/releases/tag/v11.20.0)

##### Features

- [`0b3c699`](npm/cli@0b3c699) [#9994](npm/cli#9994) token: support read-write-stage-only granular access tokens ([#9994](npm/cli#9994)) ([@github-actions](https://github.com/github-actions)\[bot], [@Tayvon](https://github.com/Tayvon), [@Copilot](https://github.com/Copilot))
- [`b872816`](npm/cli@b872816) [#9920](npm/cli#9920) stage: display staged package status ([#9920](npm/cli#9920)) ([@github-actions](https://github.com/github-actions)\[bot], [@joelverhagen](https://github.com/joelverhagen))

##### Bug Fixes

- [`ddbadfc`](npm/cli@ddbadfc) [#9947](npm/cli#9947) provenance-file takes precedence over OIDC auto-generated provenance ([#9947](npm/cli#9947)) ([@github-actions](https://github.com/github-actions)\[bot], [@yunseo-kim](https://github.com/yunseo-kim))
- [`64d4b4b`](npm/cli@64d4b4b) [#9937](npm/cli#9937) config: avoid exporting persistent allow-scripts ([#9937](npm/cli#9937)) ([@github-actions](https://github.com/github-actions)\[bot], [@Fnine59](https://github.com/Fnine59))
- [`70317da`](npm/cli@70317da) [#9930](npm/cli#9930) arborist: reject uninstall args that carry a version ([#9930](npm/cli#9930)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg))
- [`55ae484`](npm/cli@55ae484) [#9929](npm/cli#9929) arborist: match allowScripts keys for local paths ([#9929](npm/cli#9929)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))
- [`7f1f2b7`](npm/cli@7f1f2b7) [#9928](npm/cli#9928) keep dry-run output valid json ([#9928](npm/cli#9928)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm))
- [`f28cca9`](npm/cli@f28cca9) [#9927](npm/cli#9927) don't print the funding message for global installs ([#9927](npm/cli#9927)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg))

##### Chores

- [`6ff3000`](npm/cli@6ff3000) [#10010](npm/cli#10010) pack: select workspace through config ([#10010](npm/cli#10010)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi))
- [`afdc5bd`](npm/cli@afdc5bd) [#9932](npm/cli#9932) pass nodedir to node-gyp via npm_package_config env in node integration ([#9932](npm/cli#9932)) ([@reggi](https://github.com/reggi))
- [`83f95ff`](npm/cli@83f95ff) [#9931](npm/cli#9931) update `node-integration` workflow template to latest actions ([#9931](npm/cli#9931)) ([@reggi](https://github.com/reggi))
- [`f020fba`](npm/cli@f020fba) [#9925](npm/cli#9925) recognize prefixed Node.js PR titles ([#9925](npm/cli#9925)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi))

##### Dependencies

- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.2): `@npmcli/arborist@9.9.2`
- [workspace](https://github.com/npm/cli/releases/tag/config-v10.13.0): `@npmcli/config@10.13.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.13): `libnpmdiff@8.1.13`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.3): `libnpmexec@10.3.3`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.27): `libnpmfund@7.0.27`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.14): `libnpmpack@9.1.14`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.1): `libnpmpublish@11.2.1`
##### [v11.19.1](https://github.com/npm/cli/releases/tag/v11.19.1)

##### Bug Fixes

- [`83b750d`](npm/cli@83b750d) [#9916](npm/cli#9916) exempt explicit pack targets from allow-directory ([#9916](npm/cli#9916)) ([@github-actions](https://github.com/github-actions)\[bot], [@ychampion](https://github.com/ychampion), [@ychampion](https://github.com/ychampion))

##### Dependencies

- [`4791b27`](npm/cli@4791b27) [#9872](npm/cli#9872) `undici@6.28.0` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))
- [`823d647`](npm/cli@823d647) [#9872](npm/cli#9872) `ip-address@10.5.0` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))
- [`04f8efe`](npm/cli@04f8efe) [#9872](npm/cli#9872) `brace-expansion@5.0.9` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))
- [`1610280`](npm/cli@1610280) [#9842](npm/cli#9842) `tar@7.5.22` ([#9842](npm/cli#9842)) ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.13): `libnpmpack@9.1.13`
##### [v11.19.0](https://github.com/npm/cli/releases/tag/v11.19.0)

##### Features

- [`7d39aa6`](npm/cli@7d39aa6) [#9698](npm/cli#9698) install-scripts: use install-scripts as the warning log title ([@manzoorwanijk](https://github.com/manzoorwanijk))

##### Bug Fixes

- [`3529ca2`](npm/cli@3529ca2) [#9811](npm/cli#9811) pack: honor min-release-age-exclude ([#9811](npm/cli#9811)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))
- [`67f12ae`](npm/cli@67f12ae) [#9810](npm/cli#9810) owner: use scoped registry for user lookup ([#9810](npm/cli#9810)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot))

##### Dependencies

- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.1): `@npmcli/arborist@9.9.1`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.12): `libnpmdiff@8.1.12`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.2): `libnpmexec@10.3.2`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.26): `libnpmfund@7.0.26`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.12): `libnpmpack@9.1.12`
##### [v11.18.0](https://github.com/npm/cli/releases/tag/v11.18.0)

##### Features

- [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc))
- [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`9420673`](npm/cli@9420673) [#9662](npm/cli#9662) install-scripts: prune unused allowScripts entries ([#9662](npm/cli#9662)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`fc9d4c7`](npm/cli@fc9d4c7) [#9635](npm/cli#9635) namespace install-script approval commands under npm install-scripts ([#9635](npm/cli#9635)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))

##### Bug Fixes

- [`598ffdb`](npm/cli@598ffdb) [#9693](npm/cli#9693) sbom: percent-encode vcs_url qualifier in generated purls ([#9693](npm/cli#9693)) ([@github-actions](https://github.com/github-actions)\[bot], [@ubeddulla](https://github.com/ubeddulla))
- [`05793d0`](npm/cli@05793d0) [#9691](npm/cli#9691) output all the required parameters for npm token list ([#9691](npm/cli#9691)) ([@github-actions](https://github.com/github-actions)\[bot], [@rijildaniel](https://github.com/rijildaniel))
- [`cd57139`](npm/cli@cd57139) [#9669](npm/cli#9669) arborist: surface undeclared workspaces under the linked strategy (backport release/v11) ([#9669](npm/cli#9669)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`5b6ff9c`](npm/cli@5b6ff9c) [#9667](npm/cli#9667) reify: report added count for fresh linked installs ([#9667](npm/cli#9667)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk), [@owlstronaut](https://github.com/owlstronaut))
- [`8f13beb`](npm/cli@8f13beb) [#9664](npm/cli#9664) query: report logical dep location under linked strategy ([#9664](npm/cli#9664)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`168ba30`](npm/cli@168ba30) [#9663](npm/cli#9663) allowScripts: close enforcement gaps ([#9652](npm/cli#9652)) (backport release/v11) ([#9663](npm/cli#9663)) ([@JamieMagee](https://github.com/JamieMagee))
- [`ae64f88`](npm/cli@ae64f88) [#9648](npm/cli#9648) exec: resolve workspace-local bin under the linked install strategy ([#9648](npm/cli#9648)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`784cbe9`](npm/cli@784cbe9) [#9636](npm/cli#9636) ls: restore 100% coverage on release/v11 after [#9633](npm/cli#9633) ([#9636](npm/cli#9636)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`70f0ea5`](npm/cli@70f0ea5) [#9607](npm/cli#9607) approve-scripts: approve deps with no resolved URL by name ([#9607](npm/cli#9607)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`6ad5715`](npm/cli@6ad5715) [#9595](npm/cli#9595) link: scope `npm link  --workspace` to the workspace, not the root ([#9595](npm/cli#9595)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))

##### Documentation

- [`3658bb5`](npm/cli@3658bb5) [#9690](npm/cli#9690) recommend install-strategy=linked to catch phantom dependencies ([#9690](npm/cli#9690)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))

##### Dependencies

- [`54656b6`](npm/cli@54656b6) [#9696](npm/cli#9696) `undici@6.27.0`
- [`31c4773`](npm/cli@31c4773) [#9696](npm/cli#9696) `brace-expansion@5.0.7`
- [`e773c77`](npm/cli@e773c77) [#9696](npm/cli#9696) `tar@7.5.19`
- [`f05f6af`](npm/cli@f05f6af) [#9696](npm/cli#9696) `semver@7.8.5`
- [`804f9ba`](npm/cli@804f9ba) [#9580](npm/cli#9580) `npm-profile@12.0.2`

##### Chores

- [`f79b37f`](npm/cli@f79b37f) [#9696](npm/cli#9696) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut))
- [`a04cd84`](npm/cli@a04cd84) [#9584](npm/cli#9584) add web-login proxy doneUrl regression for npm-profile fix ([#9584](npm/cli#9584)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0`
- [workspace](https://github.com/npm/cli/releases/tag/config-v10.12.0): `@npmcli/config@10.12.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.11): `libnpmdiff@8.1.11`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.1): `libnpmexec@10.3.1`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.25): `libnpmfund@7.0.25`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.11): `libnpmpack@9.1.11`

arborist: 9.9.0

#### [9.9.0](npm/cli@arborist-v9.8.0...arborist-v9.9.0) (2026-06-29)

##### Features

- [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc))
- [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`9420673`](npm/cli@9420673) [#9662](npm/cli#9662) install-scripts: prune unused allowScripts entries ([#9662](npm/cli#9662)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))

##### Bug Fixes

- [`774875b`](npm/cli@774875b) [#9686](npm/cli#9686) arborist: keep bin links for allowScripts-denied packages ([#9686](npm/cli#9686)) ([@JamieMagee](https://github.com/JamieMagee))
- [`719de1e`](npm/cli@719de1e) [#9673](npm/cli#9673) arborist: apply overrides across a file: link (backport release/v11) ([#9673](npm/cli#9673)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`cd57139`](npm/cli@cd57139) [#9669](npm/cli#9669) arborist: surface undeclared workspaces under the linked strategy (backport release/v11) ([#9669](npm/cli#9669)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`ede32d3`](npm/cli@ede32d3) [#9668](npm/cli#9668) arborist: forward transitive overrides through linked store links ([#9658](npm/cli#9658)) (backport release/v11) ([#9668](npm/cli#9668)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`f503b07`](npm/cli@f503b07) [#9666](npm/cli#9666) correct dev/prod dep flags for workspaces under the linked strategy ([#9666](npm/cli#9666)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`f580889`](npm/cli@f580889) [#9665](npm/cli#9665) arborist: load transitive optional deps into linked actual tree ([#9665](npm/cli#9665)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`8f13beb`](npm/cli@8f13beb) [#9664](npm/cli#9664) query: report logical dep location under linked strategy ([#9664](npm/cli#9664)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`168ba30`](npm/cli@168ba30) [#9663](npm/cli#9663) allowScripts: close enforcement gaps ([#9652](npm/cli#9652)) (backport release/v11) ([#9663](npm/cli#9663)) ([@JamieMagee](https://github.com/JamieMagee))
- [`4c9eacb`](npm/cli@4c9eacb) [#9649](npm/cli#9649) arborist: clean up stale .store and hoisted dirs on strategy switch ([#9649](npm/cli#9649)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`d2c680e`](npm/cli@d2c680e) [#9645](npm/cli#9645) arborist: invalid filterNode crash under the linked strategy ([#9645](npm/cli#9645)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`4e40b1c`](npm/cli@4e40b1c) [#9644](npm/cli#9644) arborist: repair wrong-but-existing symlink target in linked strategy ([#9644](npm/cli#9644)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`9d1774e`](npm/cli@9d1774e) [#9643](npm/cli#9643) arborist: remove stale .bin shims after uninstall under linked ([#9643](npm/cli#9643)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`ed37d24`](npm/cli@ed37d24) [#9642](npm/cli#9642) arborist: record the linked .store layout in the hidden lockfile (backport [#9630](npm/cli#9630)) ([#9642](npm/cli#9642)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`e601d4a`](npm/cli@e601d4a) [#9641](npm/cli#9641) arborist: validate peerOptional conflicts in no-save mutations ([#9641](npm/cli#9641)) ([@owlstronaut](https://github.com/owlstronaut), [@dale-lakes](https://github.com/dale-lakes), [@dale-lakes](https://github.com/dale-lakes))
- [`03cee43`](npm/cli@03cee43) [#9638](npm/cli#9638) arborist: fix audit-report determinism due to dropped via links ([#9638](npm/cli#9638)) ([@github-actions](https://github.com/github-actions)\[bot], [@arjun-vegeta](https://github.com/arjun-vegeta))
- [`a30d855`](npm/cli@a30d855) [#9633](npm/cli#9633) arborist: don't load store packages' devDependencies as required edges ([#9633](npm/cli#9633)) ([@manzoorwanijk](https://github.com/manzoorwanijk))
- [`887ca97`](npm/cli@887ca97) [#9631](npm/cli#9631) arborist: audit the non-isolated tree under the linked strategy ([#9631](npm/cli#9631)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`390ebfa`](npm/cli@390ebfa) [#9593](npm/cli#9593) arborist: symlink workspace file: deps on non-workspace local packages ([#9593](npm/cli#9593)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`aaeb2f1`](npm/cli@aaeb2f1) [#9578](npm/cli#9578) arborist: expose store node_modules via NODE_PATH for linked-strategy install scripts ([#9578](npm/cli#9578)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`05b6f0f`](npm/cli@05b6f0f) [#9577](npm/cli#9577) arborist: allow-remote exemption for proxy/mirror-fronted registry tarballs ([#9577](npm/cli#9577)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))

config: 10.12.0

#### [10.12.0](npm/cli@config-v10.11.0...config-v10.12.0) (2026-06-29)

##### Features

- [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc))
- [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))
- [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))

##### Bug Fixes

- [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))

##### Documentation

- [`3658bb5`](npm/cli@3658bb5) [#9690](npm/cli#9690) recommend install-strategy=linked to catch phantom dependencies ([#9690](npm/cli#9690)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk))

libnpmdiff: 8.1.11

##### Dependencies

- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0`

libnpmexec: 10.3.1

#### [10.3.1](npm/cli@libnpmexec-v10.3.0...libnpmexec-v10.3.1) (2026-06-29)

##### Bug Fixes

- [`f3f2465`](npm/cli@f3f2465) [#9692](npm/cli#9692) exec: prevent shared binPaths pollution across workspace runs ([#9692](npm/cli#9692)) ([@github-actions](https://github.com/github-actions)\[bot], [@arjun-vegeta](https://github.com/arjun-vegeta))
- [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))

##### Dependencies

- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0`

libnpmfund: 7.0.25

##### Dependencies

- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0`

libnpmpack: 9.1.11

##### Dependencies

- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0`
##### [v11.17.0](https://github.com/npm/cli/releases/tag/v11.17.0)

##### Features

- [`ae8ac4e`](npm/cli@ae8ac4e) [#9534](npm/cli#9534) add min-release-age-exclude config ([@JamieMagee](https://github.com/JamieMagee), [@caseyjhol](https://github.com/caseyjhol))
- [`8ff3e48`](npm/cli@8ff3e48) [#9483](npm/cli#9483) allowScripts tooling and inBundle hardening ([#9483](npm/cli#9483)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))

##### Bug Fixes

- [`847cdf8`](npm/cli@847cdf8) [#9541](npm/cli#9541) match dotted and versioned args in approve-scripts/deny-scripts ([@owlstronaut](https://github.com/owlstronaut))
- [`d99f7cb`](npm/cli@d99f7cb) [#9535](npm/cli#9535) emit valid JSON from approve-scripts/deny-scripts --json ([@owlstronaut](https://github.com/owlstronaut))
- [`351a309`](npm/cli@351a309) [#9499](npm/cli#9499) pass script-shell to publish lifecycle hooks ([#9499](npm/cli#9499)) ([@github-actions](https://github.com/github-actions)\[bot])
- [`4fa81df`](npm/cli@4fa81df) [#9497](npm/cli#9497) recognize allowScripts for local link targets ([#9497](npm/cli#9497)) ([@github-actions](https://github.com/github-actions)\[bot], [@cyphercodes](https://github.com/cyphercodes), [@cyphercodes](https://github.com/cyphercodes))
- [`95cf2e9`](npm/cli@95cf2e9) [#9489](npm/cli#9489) validate registry path for allow-remote tarballs ([@Abhinav-143x](https://github.com/Abhinav-143x))
- [`9dd219b`](npm/cli@9dd219b) [#9462](npm/cli#9462) respect allowScripts policy in prune, dedupe, uninstall, audit, and link ([#9462](npm/cli#9462)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`cd8d18a`](npm/cli@cd8d18a) [#9482](npm/cli#9482) list pending scripts in approve-scripts when ignore-scripts is set ([#9482](npm/cli#9482)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`c14e87c`](npm/cli@c14e87c) [#9481](npm/cli#9481) suggest --allow-scripts for global installs in unreviewed-scripts warnings ([#9481](npm/cli#9481)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee))
- [`7ade52e`](npm/cli@7ade52e) [#9465](npm/cli#9465) invalid issue template YAML indentation ([#9465](npm/cli#9465)) ([@github-actions](https://github.com/github-actions)\[bot], [@fallintoplace](https://github.com/fallintoplace))
- [`c069622`](npm/cli@c069622) [#9464](npm/cli#9464) show full parent command path in subcommand usage errors ([#9464](npm/cli#9464)) ([@owlstronaut](https://github.com/owlstronaut))
- [`1bb62bb`](npm/cli@1bb62bb) [#9454](npm/cli#9454) config: clarify --all help so it's accurate for approve-scripts and deny-scripts ([@JamieMagee](https://github.com/JamieMagee))
- [`84eeb5f`](npm/cli@84eeb5f) [#9431](npm/cli#9431) audit: don't apply min-release-age before filter when verifying installed signatures ([@JamieMagee](https://github.com/JamieMagee))
- [`3bd3377`](npm/cli@3bd3377) [#9426](npm/cli#9426) block forbidden keys in Queryable setter to prevent prototype pollution ([@12122J](https://github.com/12122J), [@claude](https://github.com/claude))

##### Documentation

- [`a86a7a9`](npm/cli@a86a7a9) [#9522](npm/cli#9522) approve-scripts only throws EGLOBAL when run with -g ([@JamieMagee](https://github.com/JamieMagee))
- [`693bb3d`](npm/cli@693bb3d) [#9508](npm/cli#9508) clarify package.json override value specs ([#9508](npm/cli#9508)) ([@github-actions](https://github.com/github-actions)\[bot], [@ded-furby](https://github.com/ded-furby))
- [`ccffe4a`](npm/cli@ccffe4a) [#9501](npm/cli#9501) use the latest version for global update and outdated's `wanted` ([#9501](npm/cli#9501)) ([@github-actions](https://github.com/github-actions)\[bot], [@liangmiQwQ](https://github.com/liangmiQwQ))
- [`66e97c2`](npm/cli@66e97c2) [#9478](npm/cli#9478) update minimum npm required for npm trust ([@meeech](https://github.com/meeech))

##### Dependencies

- [`bd09b87`](npm/cli@bd09b87) [#9542](npm/cli#9542) `postcss-selector-parser@7.1.4`
- [`95bfc4c`](npm/cli@95bfc4c) [#9542](npm/cli#9542) `tinyglobby@0.2.17`
- [`8c0d5fd`](npm/cli@8c0d5fd) [#9542](npm/cli#9542) `tar@7.5.16`
- [`967d377`](npm/cli@967d377) [#9542](npm/cli#9542) `semver@7.8.4`
- [`cdaac1b`](npm/cli@cdaac1b) [#9542](npm/cli#9542) `pacote@21.5.1`
- [`25c8a9e`](npm/cli@25c8a9e) [#9542](npm/cli#9542) `node-gyp@12.4.0`

##### Chores

- [`2922fa4`](npm/cli@2922fa4) [#9542](npm/cli#9542) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.8.0): `@npmcli/arborist@9.8.0`
- [workspace](https://github.com/npm/cli/releases/tag/config-v10.11.0): `@npmcli/config@10.11.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.10): `libnpmdiff@8.1.10`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.0): `libnpmexec@10.3.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.24): `libnpmfund@7.0.24`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.10): `libnpmpack@9.1.10`
##### [v11.16.0](https://github.com/npm/cli/releases/tag/v11.16.0)

##### Features

- [`4b67f6e`](npm/cli@4b67f6e) [#9416](npm/cli#9416) publish --access=private alias for restricted ([#9416](npm/cli#9416)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot))
- [`a10c7ca`](npm/cli@a10c7ca) [#9415](npm/cli#9415) Phase 1 of `allowScripts` opt-in install-script policy ([#9360](npm/cli#9360)) ([#9415](npm/cli#9415)) ([@owlstronaut](https://github.com/owlstronaut), [@JamieMagee](https://github.com/JamieMagee))

##### Bug Fixes

- [`1f7869b`](npm/cli@1f7869b) [#9411](npm/cli#9411) fix typo of fullMetadata ([@owlstronaut](https://github.com/owlstronaut))
- [`cde03ba`](npm/cli@cde03ba) [#9390](npm/cli#9390) config: pause progress spinner during interactive editor spawn ([#9388](npm/cli#9388)) ([@github-actions](https://github.com/github-actions)\[bot], [@Zelys-DFKH](https://github.com/Zelys-DFKH), [@claude](https://github.com/claude))

##### Documentation

- [`c5e9d73`](npm/cli@c5e9d73) [#9390](npm/cli#9390) Document `npm_old_version` and `npm_new_version` environment variables ([#9389](npm/cli#9389)) ([@github-actions](https://github.com/github-actions)\[bot], [@36degrees](https://github.com/36degrees))

##### Dependencies

- [`cdd7bbc`](npm/cli@cdd7bbc) [#9421](npm/cli#9421) `undici@6.26.0`
- [`fde87c9`](npm/cli@fde87c9) [#9421](npm/cli#9421) `sigstore@4.1.1`
- [`2779793`](npm/cli@2779793) [#9421](npm/cli#9421) `lru-cache@11.5.1`
- [`dea702d`](npm/cli@dea702d) [#9421](npm/cli#9421) `@sigstore/verify@3.1.1`
- [`4eab03f`](npm/cli@4eab03f) [#9421](npm/cli#9421) `@sigstore/core@3.2.1`
- [`74c7323`](npm/cli@74c7323) [#9421](npm/cli#9421) `@npmcli/agent@4.0.2`
- [`edc4ab3`](npm/cli@edc4ab3) [#9421](npm/cli#9421) `semver@7.8.1`
- [`5f6ce33`](npm/cli@5f6ce33) [#9421](npm/cli#9421) `make-fetch-happen@15.0.6`

##### Chores

- [`bd04976`](npm/cli@bd04976) [#9421](npm/cli#9421) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut))
- [`aeceb23`](npm/cli@aeceb23) [#9407](npm/cli#9407) sanitize newlines in flags table default and type values ([#9407](npm/cli#9407)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.7.0): `@npmcli/arborist@9.7.0`
- [workspace](https://github.com/npm/cli/releases/tag/config-v10.10.0): `@npmcli/config@10.10.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.9): `libnpmdiff@8.1.9`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.9): `libnpmexec@10.2.9`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.23): `libnpmfund@7.0.23`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.9): `libnpmpack@9.1.9`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmversion-v8.0.4): `libnpmversion@8.0.4`
##### [v11.15.0](https://github.com/npm/cli/releases/tag/v11.15.0)

##### Features

- [`0d5d899`](npm/cli@0d5d899) [#9379](npm/cli#9379) npm stage ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot))
- [`1433740`](npm/cli@1433740) [#9376](npm/cli#9376) add permissions support to trust commands ([#9376](npm/cli#9376)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot))
- [`8df10f5`](npm/cli@8df10f5) [#9339](npm/cli#9339) add allow-git/allow-file/allow-directory/allow-remote configs ([@owlstronaut](https://github.com/owlstronaut))

##### Bug Fixes

- [`39b625e`](npm/cli@39b625e) [#9381](npm/cli#9381) key stage download --json output by package name ([#9381](npm/cli#9381)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot))
- [`6aa332d`](npm/cli@6aa332d) [#9339](npm/cli#9339) allow min-release-age in npmrc to coexist with --before ([@raazkhnl](https://github.com/raazkhnl))
- [`468550f`](npm/cli@468550f) [#9339](npm/cli#9339) refactor #failureNode, adjust tests and safety ([@owlstronaut](https://github.com/owlstronaut))
- [`cabe249`](npm/cli@cabe249) [#9339](npm/cli#9339) allow-remote=none does not block registry tarballs ([@owlstronaut](https://github.com/owlstronaut))

##### Dependencies

- [`8416a60`](npm/cli@8416a60) [#9383](npm/cli#9383) `socks@2.8.9`
- [`5e5a25b`](npm/cli@5e5a25b) [#9383](npm/cli#9383) `lru-cache@11.5.0`
- [`a6f9ad2`](npm/cli@a6f9ad2) [#9383](npm/cli#9383) `ip-address@10.2.0`
- [`63f8114`](npm/cli@63f8114) [#9383](npm/cli#9383) `brace-expansion@5.0.6`
- [`6918b4c`](npm/cli@6918b4c) [#9383](npm/cli#9383) `bin-links@6.0.2`
- [`bf84079`](npm/cli@bf84079) [#9383](npm/cli#9383) `tar@7.5.15`
- [`bdef82c`](npm/cli@bdef82c) [#9383](npm/cli#9383) `semver@7.8.0`
- [`3f38a67`](npm/cli@3f38a67) [#9383](npm/cli#9383) `hosted-git-info@9.0.3`

##### Chores

- [`816f3bf`](npm/cli@816f3bf) [#9383](npm/cli#9383) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.6.0): `@npmcli/arborist@9.6.0`
- [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.1): `@npmcli/config@10.9.1`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.8): `libnpmdiff@8.1.8`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.8): `libnpmexec@10.2.8`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.22): `libnpmfund@7.0.22`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.8): `libnpmpack@9.1.8`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.0): `libnpmpublish@11.2.0`
##### [v11.14.1](https://github.com/npm/cli/releases/tag/v11.14.1)

##### Bug Fixes

- [`dca12cb`](npm/cli@dca12cb) [#9328](npm/cli#9328) remove settings ([#9328](npm/cli#9328)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut))
##### [v11.14.0](https://github.com/npm/cli/releases/tag/v11.14.0)

##### Features

- [`45fc5e0`](npm/cli@45fc5e0) [#9288](npm/cli#9288) add allow-directory, allow-file, and allow-remote ([#9288](npm/cli#9288)) ([@github-actions](https://github.com/github-actions)\[bot], [@wraithgar](https://github.com/wraithgar))

##### Bug Fixes

- [`6c17544`](npm/cli@6c17544) [#9318](npm/cli#9318) sbom: dedupe per-node dependsOn / relationships ([#9318](npm/cli#9318)) ([@github-actions](https://github.com/github-actions)\[bot], [@mikaelkristiansson](https://github.com/mikaelkristiansson))

##### Dependencies

- [`840fe18`](npm/cli@840fe18) [#9322](npm/cli#9322) `socks@10.1.1`
- [`b771289`](npm/cli@b771289) [#9322](npm/cli#9322) `ip-address@10.1.1`
- [`addffcb`](npm/cli@addffcb) [#9322](npm/cli#9322) `cidr-regex@5.0.5`

##### Chores

- [`041fd58`](npm/cli@041fd58) [#9322](npm/cli#9322) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut))
- [`89c505a`](npm/cli@89c505a) [#9320](npm/cli#9320) add cli-triage team as codeowner ([#9320](npm/cli#9320)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.5.0): `@npmcli/arborist@9.5.0`
- [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.0): `@npmcli/config@10.9.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.7): `libnpmdiff@8.1.7`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.7): `libnpmexec@10.2.7`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.21): `libnpmfund@7.0.21`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.7): `libnpmpack@9.1.7`
##### [v11.13.0](https://github.com/npm/cli/releases/tag/v11.13.0)

##### Features

- [`8e8dadb`](npm/cli@8e8dadb) [#9246](npm/cli#9246) add `u` as alias for `update` command ([#9246](npm/cli#9246)) ([@github-actions](https://github.com/github-actions)\[bot], [@Ausoj](https://github.com/Ausoj))

##### Bug Fixes

- [`ecd161b`](npm/cli@ecd161b) [#9258](npm/cli#9258) ignore intended error code ([@owlstronaut](https://github.com/owlstronaut))

##### Dependencies

- [`8d2fdcd`](npm/cli@8d2fdcd) [#9272](npm/cli#9272) `lru-cache@11.3.5`
- [`e603d36`](npm/cli@e603d36) [#9272](npm/cli#9272) `node-gyp@12.3.0`
- [`d48b7da`](npm/cli@d48b7da) [#9272](npm/cli#9272) `is-cidr@6.0.4`
- [`032a5ca`](npm/cli@032a5ca) [#9240](npm/cli#9240) `@sigstore/protobuf-specs@0.5.1`
- [`33a81e7`](npm/cli@33a81e7) [#9240](npm/cli#9240) `tinyglobby@0.2.16`
- [`68dc4a0`](npm/cli@68dc4a0) [#9240](npm/cli#9240) `picomatch@4.0.4`
- [`1bb6703`](npm/cli@1bb6703) [#9240](npm/cli#9240) `lru-cache@11.3.3`
- [`37059e4`](npm/cli@37059e4) [#9240](npm/cli#9240) `diff@8.0.4`
- [`fb450ab`](npm/cli@fb450ab) [#9240](npm/cli#9240) `minimatch@10.2.5`
- [`7c4bbbf`](npm/cli@7c4bbbf) [#9240](npm/cli#9240) `tar@7.5.13`
- [`703a3bc`](npm/cli@703a3bc) [#9240](npm/cli#9240) `minipass-flush@1.0.6`

##### Chores

- [`e0724ac`](npm/cli@e0724ac) [#9272](npm/cli#9272) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut))
- [`d249341`](npm/cli@d249341) [#9230](https://github.com/npm/cli/pull/9230) don't run npm update in CI ([@owlstronaut](https://github.com/owlstronaut))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.4.3): `@npmcli/arborist@9.4.3`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.6): `libnpmdiff@8.1.6`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.6): `libnpmexec@10.2.6`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.20): `libnpmfund@7.0.20`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.6): `libnpmpack@9.1.6`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: hidden lockfile (node_modules/.package-lock.json) records the hoisted layout, not the linked layout

2 participants