Repository navigation
fix(arborist): record the linked .store layout in the hidden lockfile - #9630
Merged
owlstronaut merged 1 commit intoJun 24, 2026
Merged
owlstronaut merged 1 commit into
owlstronaut merged 1 commit into
Conversation
manzoorwanijk
force-pushed
the
fix/linked-hidden-lockfile-store-layout
branch
from
June 24, 2026 13:29
f6abc1b to
658c010
Compare
manzoorwanijk
marked this pull request as ready for review
June 24, 2026 13:33
manzoorwanijk
force-pushed
the
fix/linked-hidden-lockfile-store-layout
branch
from
June 24, 2026 14:36
658c010 to
f723efa
Compare
owlstronaut
approved these changes
Jun 24, 2026
Contributor
|
This usually means the cherry-pick had conflicts. Please create a manual backport: git fetch origin release/v11
git checkout -b backport/v11/9630 origin/release/v11
git cherry-pick -x 696801574984ad19ffaa9a7200d7e752920a018d
# resolve any conflicts, then:
git push origin backport/v11/9630Error details |
Contributor
Author
|
Creating a manual backport for this... |
Contributor
Author
|
Here you go #9642 |
owlstronaut
pushed a commit
that referenced
this pull request
Jun 24, 2026
… (backport #9630) (#9642) Backport of #9630 to `release/v11`. Under `install-strategy=linked`, the hidden lockfile `node_modules/.package-lock.json` recorded the hoisted logical layout instead of the on-disk `.store`/symlink layout, so it was rejected on every reload and never served as the actual-tree cache it is meant to be. ## How `reify.js` serializes the hidden lockfile from the isolated tree, which mirrors the on-disk layout, while `package-lock.json` still comes from the logical tree. `assertNoNewer()` additionally validates the store package node_modules and undeclared-workspace subtrees that the plain `node_modules` walk cannot reach under the linked strategy, gated so the hoisted strategy keeps its existing, stricter validation. The original commit's change to `test/arborist/reify-npm-extension.js` was dropped because the `.npm-extension` feature does not exist on `release/v11`. ## References Backport of #9630 Part of #9608
Merged
renovate Bot
added a commit
to gwennlbh/swarpc
that referenced
this pull request
Oct 7, 2026
##### [v11.21.0](npm/cli@v11.20.0...5fd1e17) ##### [v11.20.0](https://github.com/npm/cli/releases/tag/v11.20.0) ##### Features - [`0b3c699`](npm/cli@0b3c699) [#9994](npm/cli#9994) token: support read-write-stage-only granular access tokens ([#9994](npm/cli#9994)) ([@github-actions](https://github.com/github-actions)\[bot], [@Tayvon](https://github.com/Tayvon), [@Copilot](https://github.com/Copilot)) - [`b872816`](npm/cli@b872816) [#9920](npm/cli#9920) stage: display staged package status ([#9920](npm/cli#9920)) ([@github-actions](https://github.com/github-actions)\[bot], [@joelverhagen](https://github.com/joelverhagen)) ##### Bug Fixes - [`ddbadfc`](npm/cli@ddbadfc) [#9947](npm/cli#9947) provenance-file takes precedence over OIDC auto-generated provenance ([#9947](npm/cli#9947)) ([@github-actions](https://github.com/github-actions)\[bot], [@yunseo-kim](https://github.com/yunseo-kim)) - [`64d4b4b`](npm/cli@64d4b4b) [#9937](npm/cli#9937) config: avoid exporting persistent allow-scripts ([#9937](npm/cli#9937)) ([@github-actions](https://github.com/github-actions)\[bot], [@Fnine59](https://github.com/Fnine59)) - [`70317da`](npm/cli@70317da) [#9930](npm/cli#9930) arborist: reject uninstall args that carry a version ([#9930](npm/cli#9930)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg)) - [`55ae484`](npm/cli@55ae484) [#9929](npm/cli#9929) arborist: match allowScripts keys for local paths ([#9929](npm/cli#9929)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`7f1f2b7`](npm/cli@7f1f2b7) [#9928](npm/cli#9928) keep dry-run output valid json ([#9928](npm/cli#9928)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm)) - [`f28cca9`](npm/cli@f28cca9) [#9927](npm/cli#9927) don't print the funding message for global installs ([#9927](npm/cli#9927)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg)) ##### Chores - [`6ff3000`](npm/cli@6ff3000) [#10010](npm/cli#10010) pack: select workspace through config ([#10010](npm/cli#10010)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi)) - [`afdc5bd`](npm/cli@afdc5bd) [#9932](npm/cli#9932) pass nodedir to node-gyp via npm_package_config env in node integration ([#9932](npm/cli#9932)) ([@reggi](https://github.com/reggi)) - [`83f95ff`](npm/cli@83f95ff) [#9931](npm/cli#9931) update `node-integration` workflow template to latest actions ([#9931](npm/cli#9931)) ([@reggi](https://github.com/reggi)) - [`f020fba`](npm/cli@f020fba) [#9925](npm/cli#9925) recognize prefixed Node.js PR titles ([#9925](npm/cli#9925)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.2): `@npmcli/arborist@9.9.2` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.13.0): `@npmcli/config@10.13.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.13): `libnpmdiff@8.1.13` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.3): `libnpmexec@10.3.3` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.27): `libnpmfund@7.0.27` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.14): `libnpmpack@9.1.14` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.1): `libnpmpublish@11.2.1` ##### [v11.19.1](https://github.com/npm/cli/releases/tag/v11.19.1) ##### Bug Fixes - [`83b750d`](npm/cli@83b750d) [#9916](npm/cli#9916) exempt explicit pack targets from allow-directory ([#9916](npm/cli#9916)) ([@github-actions](https://github.com/github-actions)\[bot], [@ychampion](https://github.com/ychampion), [@ychampion](https://github.com/ychampion)) ##### Dependencies - [`4791b27`](npm/cli@4791b27) [#9872](npm/cli#9872) `undici@6.28.0` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`823d647`](npm/cli@823d647) [#9872](npm/cli#9872) `ip-address@10.5.0` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`04f8efe`](npm/cli@04f8efe) [#9872](npm/cli#9872) `brace-expansion@5.0.9` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`1610280`](npm/cli@1610280) [#9842](npm/cli#9842) `tar@7.5.22` ([#9842](npm/cli#9842)) ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.13): `libnpmpack@9.1.13` ##### [v11.19.0](https://github.com/npm/cli/releases/tag/v11.19.0) ##### Features - [`7d39aa6`](npm/cli@7d39aa6) [#9698](npm/cli#9698) install-scripts: use install-scripts as the warning log title ([@manzoorwanijk](https://github.com/manzoorwanijk)) ##### Bug Fixes - [`3529ca2`](npm/cli@3529ca2) [#9811](npm/cli#9811) pack: honor min-release-age-exclude ([#9811](npm/cli#9811)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`67f12ae`](npm/cli@67f12ae) [#9810](npm/cli#9810) owner: use scoped registry for user lookup ([#9810](npm/cli#9810)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.1): `@npmcli/arborist@9.9.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.12): `libnpmdiff@8.1.12` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.2): `libnpmexec@10.3.2` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.26): `libnpmfund@7.0.26` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.12): `libnpmpack@9.1.12` ##### [v11.18.0](https://github.com/npm/cli/releases/tag/v11.18.0) ##### Features - [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc)) - [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`9420673`](npm/cli@9420673) [#9662](npm/cli#9662) install-scripts: prune unused allowScripts entries ([#9662](npm/cli#9662)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`fc9d4c7`](npm/cli@fc9d4c7) [#9635](npm/cli#9635) namespace install-script approval commands under npm install-scripts ([#9635](npm/cli#9635)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`598ffdb`](npm/cli@598ffdb) [#9693](npm/cli#9693) sbom: percent-encode vcs_url qualifier in generated purls ([#9693](npm/cli#9693)) ([@github-actions](https://github.com/github-actions)\[bot], [@ubeddulla](https://github.com/ubeddulla)) - [`05793d0`](npm/cli@05793d0) [#9691](npm/cli#9691) output all the required parameters for npm token list ([#9691](npm/cli#9691)) ([@github-actions](https://github.com/github-actions)\[bot], [@rijildaniel](https://github.com/rijildaniel)) - [`cd57139`](npm/cli@cd57139) [#9669](npm/cli#9669) arborist: surface undeclared workspaces under the linked strategy (backport release/v11) ([#9669](npm/cli#9669)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`5b6ff9c`](npm/cli@5b6ff9c) [#9667](npm/cli#9667) reify: report added count for fresh linked installs ([#9667](npm/cli#9667)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk), [@owlstronaut](https://github.com/owlstronaut)) - [`8f13beb`](npm/cli@8f13beb) [#9664](npm/cli#9664) query: report logical dep location under linked strategy ([#9664](npm/cli#9664)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`168ba30`](npm/cli@168ba30) [#9663](npm/cli#9663) allowScripts: close enforcement gaps ([#9652](npm/cli#9652)) (backport release/v11) ([#9663](npm/cli#9663)) ([@JamieMagee](https://github.com/JamieMagee)) - [`ae64f88`](npm/cli@ae64f88) [#9648](npm/cli#9648) exec: resolve workspace-local bin under the linked install strategy ([#9648](npm/cli#9648)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`784cbe9`](npm/cli@784cbe9) [#9636](npm/cli#9636) ls: restore 100% coverage on release/v11 after [#9633](npm/cli#9633) ([#9636](npm/cli#9636)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`70f0ea5`](npm/cli@70f0ea5) [#9607](npm/cli#9607) approve-scripts: approve deps with no resolved URL by name ([#9607](npm/cli#9607)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`6ad5715`](npm/cli@6ad5715) [#9595](npm/cli#9595) link: scope `npm link --workspace` to the workspace, not the root ([#9595](npm/cli#9595)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) ##### Documentation - [`3658bb5`](npm/cli@3658bb5) [#9690](npm/cli#9690) recommend install-strategy=linked to catch phantom dependencies ([#9690](npm/cli#9690)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) ##### Dependencies - [`54656b6`](npm/cli@54656b6) [#9696](npm/cli#9696) `undici@6.27.0` - [`31c4773`](npm/cli@31c4773) [#9696](npm/cli#9696) `brace-expansion@5.0.7` - [`e773c77`](npm/cli@e773c77) [#9696](npm/cli#9696) `tar@7.5.19` - [`f05f6af`](npm/cli@f05f6af) [#9696](npm/cli#9696) `semver@7.8.5` - [`804f9ba`](npm/cli@804f9ba) [#9580](npm/cli#9580) `npm-profile@12.0.2` ##### Chores - [`f79b37f`](npm/cli@f79b37f) [#9696](npm/cli#9696) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`a04cd84`](npm/cli@a04cd84) [#9584](npm/cli#9584) add web-login proxy doneUrl regression for npm-profile fix ([#9584](npm/cli#9584)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.12.0): `@npmcli/config@10.12.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.11): `libnpmdiff@8.1.11` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.1): `libnpmexec@10.3.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.25): `libnpmfund@7.0.25` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.11): `libnpmpack@9.1.11` arborist: 9.9.0 #### [9.9.0](npm/cli@arborist-v9.8.0...arborist-v9.9.0) (2026-06-29) ##### Features - [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc)) - [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`9420673`](npm/cli@9420673) [#9662](npm/cli#9662) install-scripts: prune unused allowScripts entries ([#9662](npm/cli#9662)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`774875b`](npm/cli@774875b) [#9686](npm/cli#9686) arborist: keep bin links for allowScripts-denied packages ([#9686](npm/cli#9686)) ([@JamieMagee](https://github.com/JamieMagee)) - [`719de1e`](npm/cli@719de1e) [#9673](npm/cli#9673) arborist: apply overrides across a file: link (backport release/v11) ([#9673](npm/cli#9673)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`cd57139`](npm/cli@cd57139) [#9669](npm/cli#9669) arborist: surface undeclared workspaces under the linked strategy (backport release/v11) ([#9669](npm/cli#9669)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`ede32d3`](npm/cli@ede32d3) [#9668](npm/cli#9668) arborist: forward transitive overrides through linked store links ([#9658](npm/cli#9658)) (backport release/v11) ([#9668](npm/cli#9668)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`f503b07`](npm/cli@f503b07) [#9666](npm/cli#9666) correct dev/prod dep flags for workspaces under the linked strategy ([#9666](npm/cli#9666)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`f580889`](npm/cli@f580889) [#9665](npm/cli#9665) arborist: load transitive optional deps into linked actual tree ([#9665](npm/cli#9665)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`8f13beb`](npm/cli@8f13beb) [#9664](npm/cli#9664) query: report logical dep location under linked strategy ([#9664](npm/cli#9664)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`168ba30`](npm/cli@168ba30) [#9663](npm/cli#9663) allowScripts: close enforcement gaps ([#9652](npm/cli#9652)) (backport release/v11) ([#9663](npm/cli#9663)) ([@JamieMagee](https://github.com/JamieMagee)) - [`4c9eacb`](npm/cli@4c9eacb) [#9649](npm/cli#9649) arborist: clean up stale .store and hoisted dirs on strategy switch ([#9649](npm/cli#9649)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`d2c680e`](npm/cli@d2c680e) [#9645](npm/cli#9645) arborist: invalid filterNode crash under the linked strategy ([#9645](npm/cli#9645)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`4e40b1c`](npm/cli@4e40b1c) [#9644](npm/cli#9644) arborist: repair wrong-but-existing symlink target in linked strategy ([#9644](npm/cli#9644)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`9d1774e`](npm/cli@9d1774e) [#9643](npm/cli#9643) arborist: remove stale .bin shims after uninstall under linked ([#9643](npm/cli#9643)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`ed37d24`](npm/cli@ed37d24) [#9642](npm/cli#9642) arborist: record the linked .store layout in the hidden lockfile (backport [#9630](npm/cli#9630)) ([#9642](npm/cli#9642)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`e601d4a`](npm/cli@e601d4a) [#9641](npm/cli#9641) arborist: validate peerOptional conflicts in no-save mutations ([#9641](npm/cli#9641)) ([@owlstronaut](https://github.com/owlstronaut), [@dale-lakes](https://github.com/dale-lakes), [@dale-lakes](https://github.com/dale-lakes)) - [`03cee43`](npm/cli@03cee43) [#9638](npm/cli#9638) arborist: fix audit-report determinism due to dropped via links ([#9638](npm/cli#9638)) ([@github-actions](https://github.com/github-actions)\[bot], [@arjun-vegeta](https://github.com/arjun-vegeta)) - [`a30d855`](npm/cli@a30d855) [#9633](npm/cli#9633) arborist: don't load store packages' devDependencies as required edges ([#9633](npm/cli#9633)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`887ca97`](npm/cli@887ca97) [#9631](npm/cli#9631) arborist: audit the non-isolated tree under the linked strategy ([#9631](npm/cli#9631)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`390ebfa`](npm/cli@390ebfa) [#9593](npm/cli#9593) arborist: symlink workspace file: deps on non-workspace local packages ([#9593](npm/cli#9593)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`aaeb2f1`](npm/cli@aaeb2f1) [#9578](npm/cli#9578) arborist: expose store node_modules via NODE_PATH for linked-strategy install scripts ([#9578](npm/cli#9578)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`05b6f0f`](npm/cli@05b6f0f) [#9577](npm/cli#9577) arborist: allow-remote exemption for proxy/mirror-fronted registry tarballs ([#9577](npm/cli#9577)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) config: 10.12.0 #### [10.12.0](npm/cli@config-v10.11.0...config-v10.12.0) (2026-06-29) ##### Features - [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc)) - [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Documentation - [`3658bb5`](npm/cli@3658bb5) [#9690](npm/cli#9690) recommend install-strategy=linked to catch phantom dependencies ([#9690](npm/cli#9690)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) libnpmdiff: 8.1.11 ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` libnpmexec: 10.3.1 #### [10.3.1](npm/cli@libnpmexec-v10.3.0...libnpmexec-v10.3.1) (2026-06-29) ##### Bug Fixes - [`f3f2465`](npm/cli@f3f2465) [#9692](npm/cli#9692) exec: prevent shared binPaths pollution across workspace runs ([#9692](npm/cli#9692)) ([@github-actions](https://github.com/github-actions)\[bot], [@arjun-vegeta](https://github.com/arjun-vegeta)) - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` libnpmfund: 7.0.25 ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` libnpmpack: 9.1.11 ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` ##### [v11.17.0](https://github.com/npm/cli/releases/tag/v11.17.0) ##### Features - [`ae8ac4e`](npm/cli@ae8ac4e) [#9534](npm/cli#9534) add min-release-age-exclude config ([@JamieMagee](https://github.com/JamieMagee), [@caseyjhol](https://github.com/caseyjhol)) - [`8ff3e48`](npm/cli@8ff3e48) [#9483](npm/cli#9483) allowScripts tooling and inBundle hardening ([#9483](npm/cli#9483)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`847cdf8`](npm/cli@847cdf8) [#9541](npm/cli#9541) match dotted and versioned args in approve-scripts/deny-scripts ([@owlstronaut](https://github.com/owlstronaut)) - [`d99f7cb`](npm/cli@d99f7cb) [#9535](npm/cli#9535) emit valid JSON from approve-scripts/deny-scripts --json ([@owlstronaut](https://github.com/owlstronaut)) - [`351a309`](npm/cli@351a309) [#9499](npm/cli#9499) pass script-shell to publish lifecycle hooks ([#9499](npm/cli#9499)) ([@github-actions](https://github.com/github-actions)\[bot]) - [`4fa81df`](npm/cli@4fa81df) [#9497](npm/cli#9497) recognize allowScripts for local link targets ([#9497](npm/cli#9497)) ([@github-actions](https://github.com/github-actions)\[bot], [@cyphercodes](https://github.com/cyphercodes), [@cyphercodes](https://github.com/cyphercodes)) - [`95cf2e9`](npm/cli@95cf2e9) [#9489](npm/cli#9489) validate registry path for allow-remote tarballs ([@Abhinav-143x](https://github.com/Abhinav-143x)) - [`9dd219b`](npm/cli@9dd219b) [#9462](npm/cli#9462) respect allowScripts policy in prune, dedupe, uninstall, audit, and link ([#9462](npm/cli#9462)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`cd8d18a`](npm/cli@cd8d18a) [#9482](npm/cli#9482) list pending scripts in approve-scripts when ignore-scripts is set ([#9482](npm/cli#9482)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`c14e87c`](npm/cli@c14e87c) [#9481](npm/cli#9481) suggest --allow-scripts for global installs in unreviewed-scripts warnings ([#9481](npm/cli#9481)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`7ade52e`](npm/cli@7ade52e) [#9465](npm/cli#9465) invalid issue template YAML indentation ([#9465](npm/cli#9465)) ([@github-actions](https://github.com/github-actions)\[bot], [@fallintoplace](https://github.com/fallintoplace)) - [`c069622`](npm/cli@c069622) [#9464](npm/cli#9464) show full parent command path in subcommand usage errors ([#9464](npm/cli#9464)) ([@owlstronaut](https://github.com/owlstronaut)) - [`1bb62bb`](npm/cli@1bb62bb) [#9454](npm/cli#9454) config: clarify --all help so it's accurate for approve-scripts and deny-scripts ([@JamieMagee](https://github.com/JamieMagee)) - [`84eeb5f`](npm/cli@84eeb5f) [#9431](npm/cli#9431) audit: don't apply min-release-age before filter when verifying installed signatures ([@JamieMagee](https://github.com/JamieMagee)) - [`3bd3377`](npm/cli@3bd3377) [#9426](npm/cli#9426) block forbidden keys in Queryable setter to prevent prototype pollution ([@12122J](https://github.com/12122J), [@claude](https://github.com/claude)) ##### Documentation - [`a86a7a9`](npm/cli@a86a7a9) [#9522](npm/cli#9522) approve-scripts only throws EGLOBAL when run with -g ([@JamieMagee](https://github.com/JamieMagee)) - [`693bb3d`](npm/cli@693bb3d) [#9508](npm/cli#9508) clarify package.json override value specs ([#9508](npm/cli#9508)) ([@github-actions](https://github.com/github-actions)\[bot], [@ded-furby](https://github.com/ded-furby)) - [`ccffe4a`](npm/cli@ccffe4a) [#9501](npm/cli#9501) use the latest version for global update and outdated's `wanted` ([#9501](npm/cli#9501)) ([@github-actions](https://github.com/github-actions)\[bot], [@liangmiQwQ](https://github.com/liangmiQwQ)) - [`66e97c2`](npm/cli@66e97c2) [#9478](npm/cli#9478) update minimum npm required for npm trust ([@meeech](https://github.com/meeech)) ##### Dependencies - [`bd09b87`](npm/cli@bd09b87) [#9542](npm/cli#9542) `postcss-selector-parser@7.1.4` - [`95bfc4c`](npm/cli@95bfc4c) [#9542](npm/cli#9542) `tinyglobby@0.2.17` - [`8c0d5fd`](npm/cli@8c0d5fd) [#9542](npm/cli#9542) `tar@7.5.16` - [`967d377`](npm/cli@967d377) [#9542](npm/cli#9542) `semver@7.8.4` - [`cdaac1b`](npm/cli@cdaac1b) [#9542](npm/cli#9542) `pacote@21.5.1` - [`25c8a9e`](npm/cli@25c8a9e) [#9542](npm/cli#9542) `node-gyp@12.4.0` ##### Chores - [`2922fa4`](npm/cli@2922fa4) [#9542](npm/cli#9542) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.8.0): `@npmcli/arborist@9.8.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.11.0): `@npmcli/config@10.11.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.10): `libnpmdiff@8.1.10` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.0): `libnpmexec@10.3.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.24): `libnpmfund@7.0.24` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.10): `libnpmpack@9.1.10` ##### [v11.16.0](https://github.com/npm/cli/releases/tag/v11.16.0) ##### Features - [`4b67f6e`](npm/cli@4b67f6e) [#9416](npm/cli#9416) publish --access=private alias for restricted ([#9416](npm/cli#9416)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`a10c7ca`](npm/cli@a10c7ca) [#9415](npm/cli#9415) Phase 1 of `allowScripts` opt-in install-script policy ([#9360](npm/cli#9360)) ([#9415](npm/cli#9415)) ([@owlstronaut](https://github.com/owlstronaut), [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`1f7869b`](npm/cli@1f7869b) [#9411](npm/cli#9411) fix typo of fullMetadata ([@owlstronaut](https://github.com/owlstronaut)) - [`cde03ba`](npm/cli@cde03ba) [#9390](npm/cli#9390) config: pause progress spinner during interactive editor spawn ([#9388](npm/cli#9388)) ([@github-actions](https://github.com/github-actions)\[bot], [@Zelys-DFKH](https://github.com/Zelys-DFKH), [@claude](https://github.com/claude)) ##### Documentation - [`c5e9d73`](npm/cli@c5e9d73) [#9390](npm/cli#9390) Document `npm_old_version` and `npm_new_version` environment variables ([#9389](npm/cli#9389)) ([@github-actions](https://github.com/github-actions)\[bot], [@36degrees](https://github.com/36degrees)) ##### Dependencies - [`cdd7bbc`](npm/cli@cdd7bbc) [#9421](npm/cli#9421) `undici@6.26.0` - [`fde87c9`](npm/cli@fde87c9) [#9421](npm/cli#9421) `sigstore@4.1.1` - [`2779793`](npm/cli@2779793) [#9421](npm/cli#9421) `lru-cache@11.5.1` - [`dea702d`](npm/cli@dea702d) [#9421](npm/cli#9421) `@sigstore/verify@3.1.1` - [`4eab03f`](npm/cli@4eab03f) [#9421](npm/cli#9421) `@sigstore/core@3.2.1` - [`74c7323`](npm/cli@74c7323) [#9421](npm/cli#9421) `@npmcli/agent@4.0.2` - [`edc4ab3`](npm/cli@edc4ab3) [#9421](npm/cli#9421) `semver@7.8.1` - [`5f6ce33`](npm/cli@5f6ce33) [#9421](npm/cli#9421) `make-fetch-happen@15.0.6` ##### Chores - [`bd04976`](npm/cli@bd04976) [#9421](npm/cli#9421) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`aeceb23`](npm/cli@aeceb23) [#9407](npm/cli#9407) sanitize newlines in flags table default and type values ([#9407](npm/cli#9407)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.7.0): `@npmcli/arborist@9.7.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.10.0): `@npmcli/config@10.10.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.9): `libnpmdiff@8.1.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.9): `libnpmexec@10.2.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.23): `libnpmfund@7.0.23` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.9): `libnpmpack@9.1.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmversion-v8.0.4): `libnpmversion@8.0.4` ##### [v11.15.0](https://github.com/npm/cli/releases/tag/v11.15.0) ##### Features - [`0d5d899`](npm/cli@0d5d899) [#9379](npm/cli#9379) npm stage ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`1433740`](npm/cli@1433740) [#9376](npm/cli#9376) add permissions support to trust commands ([#9376](npm/cli#9376)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`8df10f5`](npm/cli@8df10f5) [#9339](npm/cli#9339) add allow-git/allow-file/allow-directory/allow-remote configs ([@owlstronaut](https://github.com/owlstronaut)) ##### Bug Fixes - [`39b625e`](npm/cli@39b625e) [#9381](npm/cli#9381) key stage download --json output by package name ([#9381](npm/cli#9381)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`6aa332d`](npm/cli@6aa332d) [#9339](npm/cli#9339) allow min-release-age in npmrc to coexist with --before ([@raazkhnl](https://github.com/raazkhnl)) - [`468550f`](npm/cli@468550f) [#9339](npm/cli#9339) refactor #failureNode, adjust tests and safety ([@owlstronaut](https://github.com/owlstronaut)) - [`cabe249`](npm/cli@cabe249) [#9339](npm/cli#9339) allow-remote=none does not block registry tarballs ([@owlstronaut](https://github.com/owlstronaut)) ##### Dependencies - [`8416a60`](npm/cli@8416a60) [#9383](npm/cli#9383) `socks@2.8.9` - [`5e5a25b`](npm/cli@5e5a25b) [#9383](npm/cli#9383) `lru-cache@11.5.0` - [`a6f9ad2`](npm/cli@a6f9ad2) [#9383](npm/cli#9383) `ip-address@10.2.0` - [`63f8114`](npm/cli@63f8114) [#9383](npm/cli#9383) `brace-expansion@5.0.6` - [`6918b4c`](npm/cli@6918b4c) [#9383](npm/cli#9383) `bin-links@6.0.2` - [`bf84079`](npm/cli@bf84079) [#9383](npm/cli#9383) `tar@7.5.15` - [`bdef82c`](npm/cli@bdef82c) [#9383](npm/cli#9383) `semver@7.8.0` - [`3f38a67`](npm/cli@3f38a67) [#9383](npm/cli#9383) `hosted-git-info@9.0.3` ##### Chores - [`816f3bf`](npm/cli@816f3bf) [#9383](npm/cli#9383) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.6.0): `@npmcli/arborist@9.6.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.1): `@npmcli/config@10.9.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.8): `libnpmdiff@8.1.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.8): `libnpmexec@10.2.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.22): `libnpmfund@7.0.22` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.8): `libnpmpack@9.1.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.0): `libnpmpublish@11.2.0` ##### [v11.14.1](https://github.com/npm/cli/releases/tag/v11.14.1) ##### Bug Fixes - [`dca12cb`](npm/cli@dca12cb) [#9328](npm/cli#9328) remove settings ([#9328](npm/cli#9328)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut)) ##### [v11.14.0](https://github.com/npm/cli/releases/tag/v11.14.0) ##### Features - [`45fc5e0`](npm/cli@45fc5e0) [#9288](npm/cli#9288) add allow-directory, allow-file, and allow-remote ([#9288](npm/cli#9288)) ([@github-actions](https://github.com/github-actions)\[bot], [@wraithgar](https://github.com/wraithgar)) ##### Bug Fixes - [`6c17544`](npm/cli@6c17544) [#9318](npm/cli#9318) sbom: dedupe per-node dependsOn / relationships ([#9318](npm/cli#9318)) ([@github-actions](https://github.com/github-actions)\[bot], [@mikaelkristiansson](https://github.com/mikaelkristiansson)) ##### Dependencies - [`840fe18`](npm/cli@840fe18) [#9322](npm/cli#9322) `socks@10.1.1` - [`b771289`](npm/cli@b771289) [#9322](npm/cli#9322) `ip-address@10.1.1` - [`addffcb`](npm/cli@addffcb) [#9322](npm/cli#9322) `cidr-regex@5.0.5` ##### Chores - [`041fd58`](npm/cli@041fd58) [#9322](npm/cli#9322) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`89c505a`](npm/cli@89c505a) [#9320](npm/cli#9320) add cli-triage team as codeowner ([#9320](npm/cli#9320)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.5.0): `@npmcli/arborist@9.5.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.0): `@npmcli/config@10.9.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.7): `libnpmdiff@8.1.7` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.7): `libnpmexec@10.2.7` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.21): `libnpmfund@7.0.21` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.7): `libnpmpack@9.1.7` ##### [v11.13.0](https://github.com/npm/cli/releases/tag/v11.13.0) ##### Features - [`8e8dadb`](npm/cli@8e8dadb) [#9246](npm/cli#9246) add `u` as alias for `update` command ([#9246](npm/cli#9246)) ([@github-actions](https://github.com/github-actions)\[bot], [@Ausoj](https://github.com/Ausoj)) ##### Bug Fixes - [`ecd161b`](npm/cli@ecd161b) [#9258](npm/cli#9258) ignore intended error code ([@owlstronaut](https://github.com/owlstronaut)) ##### Dependencies - [`8d2fdcd`](npm/cli@8d2fdcd) [#9272](npm/cli#9272) `lru-cache@11.3.5` - [`e603d36`](npm/cli@e603d36) [#9272](npm/cli#9272) `node-gyp@12.3.0` - [`d48b7da`](npm/cli@d48b7da) [#9272](npm/cli#9272) `is-cidr@6.0.4` - [`032a5ca`](npm/cli@032a5ca) [#9240](npm/cli#9240) `@sigstore/protobuf-specs@0.5.1` - [`33a81e7`](npm/cli@33a81e7) [#9240](npm/cli#9240) `tinyglobby@0.2.16` - [`68dc4a0`](npm/cli@68dc4a0) [#9240](npm/cli#9240) `picomatch@4.0.4` - [`1bb6703`](npm/cli@1bb6703) [#9240](npm/cli#9240) `lru-cache@11.3.3` - [`37059e4`](npm/cli@37059e4) [#9240](npm/cli#9240) `diff@8.0.4` - [`fb450ab`](npm/cli@fb450ab) [#9240](npm/cli#9240) `minimatch@10.2.5` - [`7c4bbbf`](npm/cli@7c4bbbf) [#9240](npm/cli#9240) `tar@7.5.13` - [`703a3bc`](npm/cli@703a3bc) [#9240](npm/cli#9240) `minipass-flush@1.0.6` ##### Chores - [`e0724ac`](npm/cli@e0724ac) [#9272](npm/cli#9272) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`d249341`](npm/cli@d249341) [#9230](https://github.com/npm/cli/pull/9230) don't run npm update in CI ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.4.3): `@npmcli/arborist@9.4.3` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.6): `libnpmdiff@8.1.6` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.6): `libnpmexec@10.2.6` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.20): `libnpmfund@7.0.20` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.6): `libnpmpack@9.1.6`
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In continuation of our exploration of using
install-strategy=linkedin the Gutenberg monorepo, which powers the WordPress Block Editor.Under
install-strategy=linked, the hidden lockfilenode_modules/.package-lock.jsonrecorded the hoisted logical layout (node_modules/<pkg>) instead of the actual on-disk.store/symlink layout. The hidden lockfile is meant to cache whatloadActual()finds on disk so the actual tree can be validated cheaply, but because it recorded the wrong layout it was rejected on every reload, so it never served as a cache and misrepresented the installed layout.Why
A linked reify swaps
idealTreefor the isolated tree, materializes the.store/symlink layout, then swaps the logical tree back before saving. The hidden lockfile was serialized from that logical tree, so it listed packages at their hoisted paths. On the next load,assertNoNewer()walked the realnode_modules(the root symlink plus.store/) and could not reconcile it with the hoisted entries, throwingmissing from lockfile, soloadActual()always fell back to a full filesystem scan.How
reify.jsserializes the hidden lockfile from the isolated tree, which mirrors the on-disk layout, whilepackage-lock.jsonstill comes from the logical tree. It records every store package directory and symlink, adds an entry for each.store/<key>container directory (these are the fsParentsloadVirtual()needs so a store package can resolve its sibling deps), includes the workspace directories, and skips tree-only undeclared-workspace self-links that are never materialized on disk.assertNoNewer()additionally validates the directories the plainnode_moduleswalk cannot reach under the linked strategy: a store package's deps live as symlinked siblings under.store/<key>/node_modules(and.storeis skipped as a dot-dir), and an undeclared workspace is not symlinked into the rootnode_modulesat all. These directories are derived from the lockfile entries. A workspace directory is only walked when it is not the target of a link entry, so the hoisted strategy keeps its existing, stricter validation unchanged — a stale workspace symlink that points at the wrong target still surfaces as a missing entry and rejects the cache.References
Fixes #9612
Part of #9608