Repository navigation
fix: provenance-file takes precedence over OIDC auto-generated provenance - #9947
Merged
Merged
Conversation
…ance (#9882) ## Why Needed When publishing with an externally generated provenance bundle under OIDC trusted publishing (`npm publish <tarball> --provenance-file=<bundle>`), npm silently discarded the supplied bundle and published its own auto-generated provenance instead. Three layers interacted: 1. `lib/utils/oidc.js` auto-enabled provenance (`opts.provenance = true`) whenever the `provenance` config was at its default, without checking whether a `provenance-file` was supplied. 2. In `libnpmpublish`'s `buildMetadata()`, the inner `provenance === true` branch then ran `generateProvenance()`, so the `verifyProvenance(subject, provenanceFile)` branch, the only code path that reads the supplied file, never executed. 3. Every documented way to disable automatic provenance was unusable in combination with `--provenance-file` (config-layer mutual exclusivity error, env carve-out, or publishConfig flatten timing). ## What Changes - **`lib/utils/oidc.js`**: skip auto-enabling provenance when a provenance file is configured (`opts.provenanceFile`). `opts` already carries `provenanceFile` from every config source (CLI/env/npmrc/publishConfig) by the time the OIDC flow runs, so this covers all entry paths. The supplied bundle is now verified via `verifyProvenance()` and published, as documented. Automatic provenance is also no longer written to the shared config; it is set only on the current publish's `opts` (which reaches libnpmpublish via `otplease`). Previously the `user`-scoped config write leaked `provenance: true` into later workspace publishes during `npm publish --workspaces`, where a workspace with `publishConfig["provenance-file"]` would then hit the conflict check below. - **`libnpmpublish`**: `buildMetadata()` now throws ~~`EPROVENANCECONFLICT`~~ `EUSAGE` (updated per review) when both `provenance: true` and `provenanceFile` are provided. - **Docs**: config descriptions for `provenance` / `provenance-file` and the libnpmpublish README now state the precedence rule. ###⚠️ ~~New error code (feedback requested)~~ Resolved: reuses `EUSAGE` ~~This PR introduces `EPROVENANCECONFLICT` in libnpmpublish, thrown when both `provenance: true` and `provenanceFile` are provided programmatically.~~ ~~**Rationale:** the README already documents the two as mutually exclusive, and silently preferring either direction discards a cryptographically meaningful artifact. Note the CLI's config layer reports the same conflict as a `TypeError` without an error code (pre-existing). Happy to align on `EUSAGE` or another convention per review.~~ **Update:** per review, the conflict reuses the existing `EUSAGE` code instead of introducing a new one (`Object.assign(new Error('provenance and provenanceFile cannot be used together'), { code: 'EUSAGE' })`), and the README documents `EUSAGE` accordingly. ## Testing - New CLI regression test: OIDC trusted publishing + `provenance-file` ~~config~~ asserts the published packument's sigstore attachment deep-equals the supplied bundle (and that sigstore generation is never invoked). **Update:** parameterized per review to cover both `provenance-file` sources, CLI config and `publishConfig`; the latter proves `publishConfig["provenance-file"]` is flattened into `opts.provenanceFile` via `Publish.#getManifest()` before `oidc()` decides whether to enable automatic provenance. - New libnpmpublish test: both options set → rejects with ~~`EPROVENANCECONFLICT`~~ `EUSAGE`, no registry PUT, generation not invoked. - New workspace regression test (per review): publishes two public workspaces in order (one where OIDC auto-enables provenance, then one with `publishConfig["provenance-file"]`), and asserts each publish receives exactly its own options (`{ provenance: true, provenanceFile: null }` then `{ provenance: false, provenanceFile }`) and that the shared config stays at its default (`npm.config.isDefault('provenance') === true`). Verified to fail on the pre-fix code for exactly the leak reason, and to pass after the fix. `mock-oidc` gained a `times` option on the GitHub id-token mock to serve one token request per workspace. - Full root suite green with 100% coverage; libnpmpublish workspace suite green; lint clean. ## References Fixes #9879 ## Out of scope (noted for follow-up) - `publishConfig.provenance: false` does not block the OIDC auto-enable (publishConfig flattens into `opts` only, so `config.isDefault('provenance')` stays true). A separate behavioral question about `isDefault` semantics. - Hardening `config.set` itself against bypassing load-time exclusivity is an `@npmcli/config` semver-major conversation; this flow no longer writes `provenance` to the config at all. --------- Signed-off-by: Yunseo Kim <git@yunseo.kim> (cherry picked from commit c9876d7)
martinrrm
approved these changes
Sep 3, 2026
Merged
This was referenced Sep 26, 2026
renovate Bot
added a commit
to gwennlbh/swarpc
that referenced
this pull request
Sep 29, 2026
##### [v11.20.0](https://github.com/npm/cli/releases/tag/v11.20.0) ##### Features - [`0b3c699`](npm/cli@0b3c699) [#9994](npm/cli#9994) token: support read-write-stage-only granular access tokens ([#9994](npm/cli#9994)) ([@github-actions](https://github.com/github-actions)\[bot], [@Tayvon](https://github.com/Tayvon), [@Copilot](https://github.com/Copilot)) - [`b872816`](npm/cli@b872816) [#9920](npm/cli#9920) stage: display staged package status ([#9920](npm/cli#9920)) ([@github-actions](https://github.com/github-actions)\[bot], [@joelverhagen](https://github.com/joelverhagen)) ##### Bug Fixes - [`ddbadfc`](npm/cli@ddbadfc) [#9947](npm/cli#9947) provenance-file takes precedence over OIDC auto-generated provenance ([#9947](npm/cli#9947)) ([@github-actions](https://github.com/github-actions)\[bot], [@yunseo-kim](https://github.com/yunseo-kim)) - [`64d4b4b`](npm/cli@64d4b4b) [#9937](npm/cli#9937) config: avoid exporting persistent allow-scripts ([#9937](npm/cli#9937)) ([@github-actions](https://github.com/github-actions)\[bot], [@Fnine59](https://github.com/Fnine59)) - [`70317da`](npm/cli@70317da) [#9930](npm/cli#9930) arborist: reject uninstall args that carry a version ([#9930](npm/cli#9930)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg)) - [`55ae484`](npm/cli@55ae484) [#9929](npm/cli#9929) arborist: match allowScripts keys for local paths ([#9929](npm/cli#9929)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`7f1f2b7`](npm/cli@7f1f2b7) [#9928](npm/cli#9928) keep dry-run output valid json ([#9928](npm/cli#9928)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm)) - [`f28cca9`](npm/cli@f28cca9) [#9927](npm/cli#9927) don't print the funding message for global installs ([#9927](npm/cli#9927)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg)) ##### Chores - [`6ff3000`](npm/cli@6ff3000) [#10010](npm/cli#10010) pack: select workspace through config ([#10010](npm/cli#10010)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi)) - [`afdc5bd`](npm/cli@afdc5bd) [#9932](npm/cli#9932) pass nodedir to node-gyp via npm\_package\_config env in node integration ([#9932](npm/cli#9932)) ([@reggi](https://github.com/reggi)) - [`83f95ff`](npm/cli@83f95ff) [#9931](npm/cli#9931) update `node-integration` workflow template to latest actions ([#9931](npm/cli#9931)) ([@reggi](https://github.com/reggi)) - [`f020fba`](npm/cli@f020fba) [#9925](npm/cli#9925) recognize prefixed Node.js PR titles ([#9925](npm/cli#9925)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.2): `@npmcli/arborist@9.9.2` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.13.0): `@npmcli/config@10.13.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.13): `libnpmdiff@8.1.13` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.3): `libnpmexec@10.3.3` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.27): `libnpmfund@7.0.27` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.14): `libnpmpack@9.1.14` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.1): `libnpmpublish@11.2.1` ##### [v11.19.1](npm/cli@v11.19.0...d63a975) ##### [v11.19.0](npm/cli@v11.18.0...6a8a1b9) ##### [v11.18.0](npm/cli@v11.17.0...fef2b13) ##### [v11.17.0](https://github.com/npm/cli/releases/tag/v11.17.0) ##### Features - [`ae8ac4e`](npm/cli@ae8ac4e) [#9534](npm/cli#9534) add min-release-age-exclude config ([@JamieMagee](https://github.com/JamieMagee), [@caseyjhol](https://github.com/caseyjhol)) - [`8ff3e48`](npm/cli@8ff3e48) [#9483](npm/cli#9483) allowScripts tooling and inBundle hardening ([#9483](npm/cli#9483)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`847cdf8`](npm/cli@847cdf8) [#9541](npm/cli#9541) match dotted and versioned args in approve-scripts/deny-scripts ([@owlstronaut](https://github.com/owlstronaut)) - [`d99f7cb`](npm/cli@d99f7cb) [#9535](npm/cli#9535) emit valid JSON from approve-scripts/deny-scripts --json ([@owlstronaut](https://github.com/owlstronaut)) - [`351a309`](npm/cli@351a309) [#9499](npm/cli#9499) pass script-shell to publish lifecycle hooks ([#9499](npm/cli#9499)) ([@github-actions](https://github.com/github-actions)\[bot]) - [`4fa81df`](npm/cli@4fa81df) [#9497](npm/cli#9497) recognize allowScripts for local link targets ([#9497](npm/cli#9497)) ([@github-actions](https://github.com/github-actions)\[bot], [@cyphercodes](https://github.com/cyphercodes), [@cyphercodes](https://github.com/cyphercodes)) - [`95cf2e9`](npm/cli@95cf2e9) [#9489](npm/cli#9489) validate registry path for allow-remote tarballs ([@Abhinav-143x](https://github.com/Abhinav-143x)) - [`9dd219b`](npm/cli@9dd219b) [#9462](npm/cli#9462) respect allowScripts policy in prune, dedupe, uninstall, audit, and link ([#9462](npm/cli#9462)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`cd8d18a`](npm/cli@cd8d18a) [#9482](npm/cli#9482) list pending scripts in approve-scripts when ignore-scripts is set ([#9482](npm/cli#9482)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`c14e87c`](npm/cli@c14e87c) [#9481](npm/cli#9481) suggest --allow-scripts for global installs in unreviewed-scripts warnings ([#9481](npm/cli#9481)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`7ade52e`](npm/cli@7ade52e) [#9465](npm/cli#9465) invalid issue template YAML indentation ([#9465](npm/cli#9465)) ([@github-actions](https://github.com/github-actions)\[bot], [@fallintoplace](https://github.com/fallintoplace)) - [`c069622`](npm/cli@c069622) [#9464](npm/cli#9464) show full parent command path in subcommand usage errors ([#9464](npm/cli#9464)) ([@owlstronaut](https://github.com/owlstronaut)) - [`1bb62bb`](npm/cli@1bb62bb) [#9454](npm/cli#9454) config: clarify --all help so it's accurate for approve-scripts and deny-scripts ([@JamieMagee](https://github.com/JamieMagee)) - [`84eeb5f`](npm/cli@84eeb5f) [#9431](npm/cli#9431) audit: don't apply min-release-age before filter when verifying installed signatures ([@JamieMagee](https://github.com/JamieMagee)) - [`3bd3377`](npm/cli@3bd3377) [#9426](npm/cli#9426) block forbidden keys in Queryable setter to prevent prototype pollution ([@12122J](https://github.com/12122J), [@claude](https://github.com/claude)) ##### Documentation - [`a86a7a9`](npm/cli@a86a7a9) [#9522](npm/cli#9522) approve-scripts only throws EGLOBAL when run with -g ([@JamieMagee](https://github.com/JamieMagee)) - [`693bb3d`](npm/cli@693bb3d) [#9508](npm/cli#9508) clarify package.json override value specs ([#9508](npm/cli#9508)) ([@github-actions](https://github.com/github-actions)\[bot], [@ded-furby](https://github.com/ded-furby)) - [`ccffe4a`](npm/cli@ccffe4a) [#9501](npm/cli#9501) use the latest version for global update and outdated's `wanted` ([#9501](npm/cli#9501)) ([@github-actions](https://github.com/github-actions)\[bot], [@liangmiQwQ](https://github.com/liangmiQwQ)) - [`66e97c2`](npm/cli@66e97c2) [#9478](npm/cli#9478) update minimum npm required for npm trust ([@meeech](https://github.com/meeech)) ##### Dependencies - [`bd09b87`](npm/cli@bd09b87) [#9542](npm/cli#9542) `postcss-selector-parser@7.1.4` - [`95bfc4c`](npm/cli@95bfc4c) [#9542](npm/cli#9542) `tinyglobby@0.2.17` - [`8c0d5fd`](npm/cli@8c0d5fd) [#9542](npm/cli#9542) `tar@7.5.16` - [`967d377`](npm/cli@967d377) [#9542](npm/cli#9542) `semver@7.8.4` - [`cdaac1b`](npm/cli@cdaac1b) [#9542](npm/cli#9542) `pacote@21.5.1` - [`25c8a9e`](npm/cli@25c8a9e) [#9542](npm/cli#9542) `node-gyp@12.4.0` ##### Chores - [`2922fa4`](npm/cli@2922fa4) [#9542](npm/cli#9542) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.8.0): `@npmcli/arborist@9.8.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.11.0): `@npmcli/config@10.11.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.10): `libnpmdiff@8.1.10` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.0): `libnpmexec@10.3.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.24): `libnpmfund@7.0.24` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.10): `libnpmpack@9.1.10` ##### [v11.16.0](https://github.com/npm/cli/releases/tag/v11.16.0) ##### Features - [`4b67f6e`](npm/cli@4b67f6e) [#9416](npm/cli#9416) publish --access=private alias for restricted ([#9416](npm/cli#9416)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`a10c7ca`](npm/cli@a10c7ca) [#9415](npm/cli#9415) Phase 1 of `allowScripts` opt-in install-script policy ([#9360](npm/cli#9360)) ([#9415](npm/cli#9415)) ([@owlstronaut](https://github.com/owlstronaut), [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`1f7869b`](npm/cli@1f7869b) [#9411](npm/cli#9411) fix typo of fullMetadata ([@owlstronaut](https://github.com/owlstronaut)) - [`cde03ba`](npm/cli@cde03ba) [#9390](npm/cli#9390) config: pause progress spinner during interactive editor spawn ([#9388](npm/cli#9388)) ([@github-actions](https://github.com/github-actions)\[bot], [@Zelys-DFKH](https://github.com/Zelys-DFKH), [@claude](https://github.com/claude)) ##### Documentation - [`c5e9d73`](npm/cli@c5e9d73) [#9390](npm/cli#9390) Document `npm_old_version` and `npm_new_version` environment variables ([#9389](npm/cli#9389)) ([@github-actions](https://github.com/github-actions)\[bot], [@36degrees](https://github.com/36degrees)) ##### Dependencies - [`cdd7bbc`](npm/cli@cdd7bbc) [#9421](npm/cli#9421) `undici@6.26.0` - [`fde87c9`](npm/cli@fde87c9) [#9421](npm/cli#9421) `sigstore@4.1.1` - [`2779793`](npm/cli@2779793) [#9421](npm/cli#9421) `lru-cache@11.5.1` - [`dea702d`](npm/cli@dea702d) [#9421](npm/cli#9421) `@sigstore/verify@3.1.1` - [`4eab03f`](npm/cli@4eab03f) [#9421](npm/cli#9421) `@sigstore/core@3.2.1` - [`74c7323`](npm/cli@74c7323) [#9421](npm/cli#9421) `@npmcli/agent@4.0.2` - [`edc4ab3`](npm/cli@edc4ab3) [#9421](npm/cli#9421) `semver@7.8.1` - [`5f6ce33`](npm/cli@5f6ce33) [#9421](npm/cli#9421) `make-fetch-happen@15.0.6` ##### Chores - [`bd04976`](npm/cli@bd04976) [#9421](npm/cli#9421) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`aeceb23`](npm/cli@aeceb23) [#9407](npm/cli#9407) sanitize newlines in flags table default and type values ([#9407](npm/cli#9407)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.7.0): `@npmcli/arborist@9.7.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.10.0): `@npmcli/config@10.10.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.9): `libnpmdiff@8.1.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.9): `libnpmexec@10.2.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.23): `libnpmfund@7.0.23` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.9): `libnpmpack@9.1.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmversion-v8.0.4): `libnpmversion@8.0.4` ##### [v11.15.0](https://github.com/npm/cli/releases/tag/v11.15.0) ##### Features - [`0d5d899`](npm/cli@0d5d899) [#9379](npm/cli#9379) npm stage ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`1433740`](npm/cli@1433740) [#9376](npm/cli#9376) add permissions support to trust commands ([#9376](npm/cli#9376)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`8df10f5`](npm/cli@8df10f5) [#9339](npm/cli#9339) add allow-git/allow-file/allow-directory/allow-remote configs ([@owlstronaut](https://github.com/owlstronaut)) ##### Bug Fixes - [`39b625e`](npm/cli@39b625e) [#9381](npm/cli#9381) key stage download --json output by package name ([#9381](npm/cli#9381)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`6aa332d`](npm/cli@6aa332d) [#9339](npm/cli#9339) allow min-release-age in npmrc to coexist with --before ([@raazkhnl](https://github.com/raazkhnl)) - [`468550f`](npm/cli@468550f) [#9339](npm/cli#9339) refactor #failureNode, adjust tests and safety ([@owlstronaut](https://github.com/owlstronaut)) - [`cabe249`](npm/cli@cabe249) [#9339](npm/cli#9339) allow-remote=none does not block registry tarballs ([@owlstronaut](https://github.com/owlstronaut)) ##### Dependencies - [`8416a60`](npm/cli@8416a60) [#9383](npm/cli#9383) `socks@2.8.9` - [`5e5a25b`](npm/cli@5e5a25b) [#9383](npm/cli#9383) `lru-cache@11.5.0` - [`a6f9ad2`](npm/cli@a6f9ad2) [#9383](npm/cli#9383) `ip-address@10.2.0` - [`63f8114`](npm/cli@63f8114) [#9383](npm/cli#9383) `brace-expansion@5.0.6` - [`6918b4c`](npm/cli@6918b4c) [#9383](npm/cli#9383) `bin-links@6.0.2` - [`bf84079`](npm/cli@bf84079) [#9383](npm/cli#9383) `tar@7.5.15` - [`bdef82c`](npm/cli@bdef82c) [#9383](npm/cli#9383) `semver@7.8.0` - [`3f38a67`](npm/cli@3f38a67) [#9383](npm/cli#9383) `hosted-git-info@9.0.3` ##### Chores - [`816f3bf`](npm/cli@816f3bf) [#9383](npm/cli#9383) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.6.0): `@npmcli/arborist@9.6.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.1): `@npmcli/config@10.9.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.8): `libnpmdiff@8.1.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.8): `libnpmexec@10.2.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.22): `libnpmfund@7.0.22` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.8): `libnpmpack@9.1.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.0): `libnpmpublish@11.2.0` ##### [v11.14.1](https://github.com/npm/cli/releases/tag/v11.14.1) ##### Bug Fixes - [`dca12cb`](npm/cli@dca12cb) [#9328](npm/cli#9328) remove settings ([#9328](npm/cli#9328)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut)) ##### [v11.14.0](https://github.com/npm/cli/releases/tag/v11.14.0) ##### Features - [`45fc5e0`](npm/cli@45fc5e0) [#9288](npm/cli#9288) add allow-directory, allow-file, and allow-remote ([#9288](npm/cli#9288)) ([@github-actions](https://github.com/github-actions)\[bot], [@wraithgar](https://github.com/wraithgar)) ##### Bug Fixes - [`6c17544`](npm/cli@6c17544) [#9318](npm/cli#9318) sbom: dedupe per-node dependsOn / relationships ([#9318](npm/cli#9318)) ([@github-actions](https://github.com/github-actions)\[bot], [@mikaelkristiansson](https://github.com/mikaelkristiansson)) ##### Dependencies - [`840fe18`](npm/cli@840fe18) [#9322](npm/cli#9322) `socks@10.1.1` - [`b771289`](npm/cli@b771289) [#9322](npm/cli#9322) `ip-address@10.1.1` - [`addffcb`](npm/cli@addffcb) [#9322](npm/cli#9322) `cidr-regex@5.0.5` ##### Chores - [`041fd58`](npm/cli@041fd58) [#9322](npm/cli#9322) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`89c505a`](npm/cli@89c505a) [#9320](npm/cli#9320) add cli-triage team as codeowner ([#9320](npm/cli#9320)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.5.0): `@npmcli/arborist@9.5.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.0): `@npmcli/config@10.9.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.7): `libnpmdiff@8.1.7` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.7): `libnpmexec@10.2.7` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.21): `libnpmfund@7.0.21` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.7): `libnpmpack@9.1.7` ##### [v11.13.0](https://github.com/npm/cli/releases/tag/v11.13.0) ##### Features - [`8e8dadb`](npm/cli@8e8dadb) [#9246](npm/cli#9246) add `u` as alias for `update` command ([#9246](npm/cli#9246)) ([@github-actions](https://github.com/github-actions)\[bot], [@Ausoj](https://github.com/Ausoj)) ##### Bug Fixes - [`ecd161b`](npm/cli@ecd161b) [#9258](npm/cli#9258) ignore intended error code ([@owlstronaut](https://github.com/owlstronaut)) ##### Dependencies - [`8d2fdcd`](npm/cli@8d2fdcd) [#9272](npm/cli#9272) `lru-cache@11.3.5` - [`e603d36`](npm/cli@e603d36) [#9272](npm/cli#9272) `node-gyp@12.3.0` - [`d48b7da`](npm/cli@d48b7da) [#9272](npm/cli#9272) `is-cidr@6.0.4` - [`032a5ca`](npm/cli@032a5ca) [#9240](npm/cli#9240) `@sigstore/protobuf-specs@0.5.1` - [`33a81e7`](npm/cli@33a81e7) [#9240](npm/cli#9240) `tinyglobby@0.2.16` - [`68dc4a0`](npm/cli@68dc4a0) [#9240](npm/cli#9240) `picomatch@4.0.4` - [`1bb6703`](npm/cli@1bb6703) [#9240](npm/cli#9240) `lru-cache@11.3.3` - [`37059e4`](npm/cli@37059e4) [#9240](npm/cli#9240) `diff@8.0.4` - [`fb450ab`](npm/cli@fb450ab) [#9240](npm/cli#9240) `minimatch@10.2.5` - [`7c4bbbf`](npm/cli@7c4bbbf) [#9240](npm/cli#9240) `tar@7.5.13` - [`703a3bc`](npm/cli@703a3bc) [#9240](npm/cli#9240) `minipass-flush@1.0.6` ##### Chores - [`e0724ac`](npm/cli@e0724ac) [#9272](npm/cli#9272) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`d249341`](npm/cli@d249341) [#9230](npm/cli#9230) don't run npm update in CI ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.4.3): `@npmcli/arborist@9.4.3` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.6): `libnpmdiff@8.1.6` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.6): `libnpmexec@10.2.6` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.20): `libnpmfund@7.0.20` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.6): `libnpmpack@9.1.6`
renovate Bot
added a commit
to gwennlbh/swarpc
that referenced
this pull request
Oct 7, 2026
##### [v11.21.0](npm/cli@v11.20.0...5fd1e17) ##### [v11.20.0](https://github.com/npm/cli/releases/tag/v11.20.0) ##### Features - [`0b3c699`](npm/cli@0b3c699) [#9994](npm/cli#9994) token: support read-write-stage-only granular access tokens ([#9994](npm/cli#9994)) ([@github-actions](https://github.com/github-actions)\[bot], [@Tayvon](https://github.com/Tayvon), [@Copilot](https://github.com/Copilot)) - [`b872816`](npm/cli@b872816) [#9920](npm/cli#9920) stage: display staged package status ([#9920](npm/cli#9920)) ([@github-actions](https://github.com/github-actions)\[bot], [@joelverhagen](https://github.com/joelverhagen)) ##### Bug Fixes - [`ddbadfc`](npm/cli@ddbadfc) [#9947](npm/cli#9947) provenance-file takes precedence over OIDC auto-generated provenance ([#9947](npm/cli#9947)) ([@github-actions](https://github.com/github-actions)\[bot], [@yunseo-kim](https://github.com/yunseo-kim)) - [`64d4b4b`](npm/cli@64d4b4b) [#9937](npm/cli#9937) config: avoid exporting persistent allow-scripts ([#9937](npm/cli#9937)) ([@github-actions](https://github.com/github-actions)\[bot], [@Fnine59](https://github.com/Fnine59)) - [`70317da`](npm/cli@70317da) [#9930](npm/cli#9930) arborist: reject uninstall args that carry a version ([#9930](npm/cli#9930)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg)) - [`55ae484`](npm/cli@55ae484) [#9929](npm/cli#9929) arborist: match allowScripts keys for local paths ([#9929](npm/cli#9929)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`7f1f2b7`](npm/cli@7f1f2b7) [#9928](npm/cli#9928) keep dry-run output valid json ([#9928](npm/cli#9928)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm)) - [`f28cca9`](npm/cli@f28cca9) [#9927](npm/cli#9927) don't print the funding message for global installs ([#9927](npm/cli#9927)) ([@github-actions](https://github.com/github-actions)\[bot], [@lazerg](https://github.com/lazerg)) ##### Chores - [`6ff3000`](npm/cli@6ff3000) [#10010](npm/cli#10010) pack: select workspace through config ([#10010](npm/cli#10010)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi)) - [`afdc5bd`](npm/cli@afdc5bd) [#9932](npm/cli#9932) pass nodedir to node-gyp via npm_package_config env in node integration ([#9932](npm/cli#9932)) ([@reggi](https://github.com/reggi)) - [`83f95ff`](npm/cli@83f95ff) [#9931](npm/cli#9931) update `node-integration` workflow template to latest actions ([#9931](npm/cli#9931)) ([@reggi](https://github.com/reggi)) - [`f020fba`](npm/cli@f020fba) [#9925](npm/cli#9925) recognize prefixed Node.js PR titles ([#9925](npm/cli#9925)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.2): `@npmcli/arborist@9.9.2` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.13.0): `@npmcli/config@10.13.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.13): `libnpmdiff@8.1.13` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.3): `libnpmexec@10.3.3` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.27): `libnpmfund@7.0.27` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.14): `libnpmpack@9.1.14` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.1): `libnpmpublish@11.2.1` ##### [v11.19.1](https://github.com/npm/cli/releases/tag/v11.19.1) ##### Bug Fixes - [`83b750d`](npm/cli@83b750d) [#9916](npm/cli#9916) exempt explicit pack targets from allow-directory ([#9916](npm/cli#9916)) ([@github-actions](https://github.com/github-actions)\[bot], [@ychampion](https://github.com/ychampion), [@ychampion](https://github.com/ychampion)) ##### Dependencies - [`4791b27`](npm/cli@4791b27) [#9872](npm/cli#9872) `undici@6.28.0` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`823d647`](npm/cli@823d647) [#9872](npm/cli#9872) `ip-address@10.5.0` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`04f8efe`](npm/cli@04f8efe) [#9872](npm/cli#9872) `brace-expansion@5.0.9` ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`1610280`](npm/cli@1610280) [#9842](npm/cli#9842) `tar@7.5.22` ([#9842](npm/cli#9842)) ([@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.13): `libnpmpack@9.1.13` ##### [v11.19.0](https://github.com/npm/cli/releases/tag/v11.19.0) ##### Features - [`7d39aa6`](npm/cli@7d39aa6) [#9698](npm/cli#9698) install-scripts: use install-scripts as the warning log title ([@manzoorwanijk](https://github.com/manzoorwanijk)) ##### Bug Fixes - [`3529ca2`](npm/cli@3529ca2) [#9811](npm/cli#9811) pack: honor min-release-age-exclude ([#9811](npm/cli#9811)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) - [`67f12ae`](npm/cli@67f12ae) [#9810](npm/cli#9810) owner: use scoped registry for user lookup ([#9810](npm/cli#9810)) ([@github-actions](https://github.com/github-actions)\[bot], [@martinrrm](https://github.com/martinrrm), [@Copilot](https://github.com/Copilot)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.1): `@npmcli/arborist@9.9.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.12): `libnpmdiff@8.1.12` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.2): `libnpmexec@10.3.2` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.26): `libnpmfund@7.0.26` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.12): `libnpmpack@9.1.12` ##### [v11.18.0](https://github.com/npm/cli/releases/tag/v11.18.0) ##### Features - [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc)) - [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`9420673`](npm/cli@9420673) [#9662](npm/cli#9662) install-scripts: prune unused allowScripts entries ([#9662](npm/cli#9662)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`fc9d4c7`](npm/cli@fc9d4c7) [#9635](npm/cli#9635) namespace install-script approval commands under npm install-scripts ([#9635](npm/cli#9635)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`598ffdb`](npm/cli@598ffdb) [#9693](npm/cli#9693) sbom: percent-encode vcs_url qualifier in generated purls ([#9693](npm/cli#9693)) ([@github-actions](https://github.com/github-actions)\[bot], [@ubeddulla](https://github.com/ubeddulla)) - [`05793d0`](npm/cli@05793d0) [#9691](npm/cli#9691) output all the required parameters for npm token list ([#9691](npm/cli#9691)) ([@github-actions](https://github.com/github-actions)\[bot], [@rijildaniel](https://github.com/rijildaniel)) - [`cd57139`](npm/cli@cd57139) [#9669](npm/cli#9669) arborist: surface undeclared workspaces under the linked strategy (backport release/v11) ([#9669](npm/cli#9669)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`5b6ff9c`](npm/cli@5b6ff9c) [#9667](npm/cli#9667) reify: report added count for fresh linked installs ([#9667](npm/cli#9667)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk), [@owlstronaut](https://github.com/owlstronaut)) - [`8f13beb`](npm/cli@8f13beb) [#9664](npm/cli#9664) query: report logical dep location under linked strategy ([#9664](npm/cli#9664)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`168ba30`](npm/cli@168ba30) [#9663](npm/cli#9663) allowScripts: close enforcement gaps ([#9652](npm/cli#9652)) (backport release/v11) ([#9663](npm/cli#9663)) ([@JamieMagee](https://github.com/JamieMagee)) - [`ae64f88`](npm/cli@ae64f88) [#9648](npm/cli#9648) exec: resolve workspace-local bin under the linked install strategy ([#9648](npm/cli#9648)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`784cbe9`](npm/cli@784cbe9) [#9636](npm/cli#9636) ls: restore 100% coverage on release/v11 after [#9633](npm/cli#9633) ([#9636](npm/cli#9636)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`70f0ea5`](npm/cli@70f0ea5) [#9607](npm/cli#9607) approve-scripts: approve deps with no resolved URL by name ([#9607](npm/cli#9607)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`6ad5715`](npm/cli@6ad5715) [#9595](npm/cli#9595) link: scope `npm link --workspace` to the workspace, not the root ([#9595](npm/cli#9595)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) ##### Documentation - [`3658bb5`](npm/cli@3658bb5) [#9690](npm/cli#9690) recommend install-strategy=linked to catch phantom dependencies ([#9690](npm/cli#9690)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) ##### Dependencies - [`54656b6`](npm/cli@54656b6) [#9696](npm/cli#9696) `undici@6.27.0` - [`31c4773`](npm/cli@31c4773) [#9696](npm/cli#9696) `brace-expansion@5.0.7` - [`e773c77`](npm/cli@e773c77) [#9696](npm/cli#9696) `tar@7.5.19` - [`f05f6af`](npm/cli@f05f6af) [#9696](npm/cli#9696) `semver@7.8.5` - [`804f9ba`](npm/cli@804f9ba) [#9580](npm/cli#9580) `npm-profile@12.0.2` ##### Chores - [`f79b37f`](npm/cli@f79b37f) [#9696](npm/cli#9696) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`a04cd84`](npm/cli@a04cd84) [#9584](npm/cli#9584) add web-login proxy doneUrl regression for npm-profile fix ([#9584](npm/cli#9584)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.12.0): `@npmcli/config@10.12.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.11): `libnpmdiff@8.1.11` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.1): `libnpmexec@10.3.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.25): `libnpmfund@7.0.25` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.11): `libnpmpack@9.1.11` arborist: 9.9.0 #### [9.9.0](npm/cli@arborist-v9.8.0...arborist-v9.9.0) (2026-06-29) ##### Features - [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc)) - [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`9420673`](npm/cli@9420673) [#9662](npm/cli#9662) install-scripts: prune unused allowScripts entries ([#9662](npm/cli#9662)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`774875b`](npm/cli@774875b) [#9686](npm/cli#9686) arborist: keep bin links for allowScripts-denied packages ([#9686](npm/cli#9686)) ([@JamieMagee](https://github.com/JamieMagee)) - [`719de1e`](npm/cli@719de1e) [#9673](npm/cli#9673) arborist: apply overrides across a file: link (backport release/v11) ([#9673](npm/cli#9673)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`cd57139`](npm/cli@cd57139) [#9669](npm/cli#9669) arborist: surface undeclared workspaces under the linked strategy (backport release/v11) ([#9669](npm/cli#9669)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`ede32d3`](npm/cli@ede32d3) [#9668](npm/cli#9668) arborist: forward transitive overrides through linked store links ([#9658](npm/cli#9658)) (backport release/v11) ([#9668](npm/cli#9668)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`f503b07`](npm/cli@f503b07) [#9666](npm/cli#9666) correct dev/prod dep flags for workspaces under the linked strategy ([#9666](npm/cli#9666)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`f580889`](npm/cli@f580889) [#9665](npm/cli#9665) arborist: load transitive optional deps into linked actual tree ([#9665](npm/cli#9665)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`8f13beb`](npm/cli@8f13beb) [#9664](npm/cli#9664) query: report logical dep location under linked strategy ([#9664](npm/cli#9664)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`168ba30`](npm/cli@168ba30) [#9663](npm/cli#9663) allowScripts: close enforcement gaps ([#9652](npm/cli#9652)) (backport release/v11) ([#9663](npm/cli#9663)) ([@JamieMagee](https://github.com/JamieMagee)) - [`4c9eacb`](npm/cli@4c9eacb) [#9649](npm/cli#9649) arborist: clean up stale .store and hoisted dirs on strategy switch ([#9649](npm/cli#9649)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`d2c680e`](npm/cli@d2c680e) [#9645](npm/cli#9645) arborist: invalid filterNode crash under the linked strategy ([#9645](npm/cli#9645)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`4e40b1c`](npm/cli@4e40b1c) [#9644](npm/cli#9644) arborist: repair wrong-but-existing symlink target in linked strategy ([#9644](npm/cli#9644)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`9d1774e`](npm/cli@9d1774e) [#9643](npm/cli#9643) arborist: remove stale .bin shims after uninstall under linked ([#9643](npm/cli#9643)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`ed37d24`](npm/cli@ed37d24) [#9642](npm/cli#9642) arborist: record the linked .store layout in the hidden lockfile (backport [#9630](npm/cli#9630)) ([#9642](npm/cli#9642)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`e601d4a`](npm/cli@e601d4a) [#9641](npm/cli#9641) arborist: validate peerOptional conflicts in no-save mutations ([#9641](npm/cli#9641)) ([@owlstronaut](https://github.com/owlstronaut), [@dale-lakes](https://github.com/dale-lakes), [@dale-lakes](https://github.com/dale-lakes)) - [`03cee43`](npm/cli@03cee43) [#9638](npm/cli#9638) arborist: fix audit-report determinism due to dropped via links ([#9638](npm/cli#9638)) ([@github-actions](https://github.com/github-actions)\[bot], [@arjun-vegeta](https://github.com/arjun-vegeta)) - [`a30d855`](npm/cli@a30d855) [#9633](npm/cli#9633) arborist: don't load store packages' devDependencies as required edges ([#9633](npm/cli#9633)) ([@manzoorwanijk](https://github.com/manzoorwanijk)) - [`887ca97`](npm/cli@887ca97) [#9631](npm/cli#9631) arborist: audit the non-isolated tree under the linked strategy ([#9631](npm/cli#9631)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`390ebfa`](npm/cli@390ebfa) [#9593](npm/cli#9593) arborist: symlink workspace file: deps on non-workspace local packages ([#9593](npm/cli#9593)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`aaeb2f1`](npm/cli@aaeb2f1) [#9578](npm/cli#9578) arborist: expose store node_modules via NODE_PATH for linked-strategy install scripts ([#9578](npm/cli#9578)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`05b6f0f`](npm/cli@05b6f0f) [#9577](npm/cli#9577) arborist: allow-remote exemption for proxy/mirror-fronted registry tarballs ([#9577](npm/cli#9577)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) config: 10.12.0 #### [10.12.0](npm/cli@config-v10.11.0...config-v10.12.0) (2026-06-29) ##### Features - [`3021ad6`](npm/cli@3021ad6) [#9694](npm/cli#9694) arborist: extend replace-registry-host with URL prefix matching ([#6110](npm/cli#6110)) ([#9694](npm/cli#9694)) ([@github-actions](https://github.com/github-actions)\[bot], [@u2mejc](https://github.com/u2mejc)) - [`abd8c6b`](npm/cli@abd8c6b) [#9677](npm/cli#9677) graduate the linked install strategy from experimental to stable ([#9677](npm/cli#9677)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) - [`073253f`](npm/cli@073253f) [#9564](npm/cli#9564) warn when min-release-age blocks an audit fix ([#9564](npm/cli#9564)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Documentation - [`3658bb5`](npm/cli@3658bb5) [#9690](npm/cli#9690) recommend install-strategy=linked to catch phantom dependencies ([#9690](npm/cli#9690)) ([@github-actions](https://github.com/github-actions)\[bot], [@manzoorwanijk](https://github.com/manzoorwanijk)) libnpmdiff: 8.1.11 ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` libnpmexec: 10.3.1 #### [10.3.1](npm/cli@libnpmexec-v10.3.0...libnpmexec-v10.3.1) (2026-06-29) ##### Bug Fixes - [`f3f2465`](npm/cli@f3f2465) [#9692](npm/cli#9692) exec: prevent shared binPaths pollution across workspace runs ([#9692](npm/cli#9692)) ([@github-actions](https://github.com/github-actions)\[bot], [@arjun-vegeta](https://github.com/arjun-vegeta)) - [`b2e6338`](npm/cli@b2e6338) [#9602](npm/cli#9602) arborist: don't flag inert optional deps in strict-allow-scripts ([#9602](npm/cli#9602)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` libnpmfund: 7.0.25 ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` libnpmpack: 9.1.11 ##### Dependencies - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.9.0): `@npmcli/arborist@9.9.0` ##### [v11.17.0](https://github.com/npm/cli/releases/tag/v11.17.0) ##### Features - [`ae8ac4e`](npm/cli@ae8ac4e) [#9534](npm/cli#9534) add min-release-age-exclude config ([@JamieMagee](https://github.com/JamieMagee), [@caseyjhol](https://github.com/caseyjhol)) - [`8ff3e48`](npm/cli@8ff3e48) [#9483](npm/cli#9483) allowScripts tooling and inBundle hardening ([#9483](npm/cli#9483)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`847cdf8`](npm/cli@847cdf8) [#9541](npm/cli#9541) match dotted and versioned args in approve-scripts/deny-scripts ([@owlstronaut](https://github.com/owlstronaut)) - [`d99f7cb`](npm/cli@d99f7cb) [#9535](npm/cli#9535) emit valid JSON from approve-scripts/deny-scripts --json ([@owlstronaut](https://github.com/owlstronaut)) - [`351a309`](npm/cli@351a309) [#9499](npm/cli#9499) pass script-shell to publish lifecycle hooks ([#9499](npm/cli#9499)) ([@github-actions](https://github.com/github-actions)\[bot]) - [`4fa81df`](npm/cli@4fa81df) [#9497](npm/cli#9497) recognize allowScripts for local link targets ([#9497](npm/cli#9497)) ([@github-actions](https://github.com/github-actions)\[bot], [@cyphercodes](https://github.com/cyphercodes), [@cyphercodes](https://github.com/cyphercodes)) - [`95cf2e9`](npm/cli@95cf2e9) [#9489](npm/cli#9489) validate registry path for allow-remote tarballs ([@Abhinav-143x](https://github.com/Abhinav-143x)) - [`9dd219b`](npm/cli@9dd219b) [#9462](npm/cli#9462) respect allowScripts policy in prune, dedupe, uninstall, audit, and link ([#9462](npm/cli#9462)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`cd8d18a`](npm/cli@cd8d18a) [#9482](npm/cli#9482) list pending scripts in approve-scripts when ignore-scripts is set ([#9482](npm/cli#9482)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`c14e87c`](npm/cli@c14e87c) [#9481](npm/cli#9481) suggest --allow-scripts for global installs in unreviewed-scripts warnings ([#9481](npm/cli#9481)) ([@github-actions](https://github.com/github-actions)\[bot], [@JamieMagee](https://github.com/JamieMagee)) - [`7ade52e`](npm/cli@7ade52e) [#9465](npm/cli#9465) invalid issue template YAML indentation ([#9465](npm/cli#9465)) ([@github-actions](https://github.com/github-actions)\[bot], [@fallintoplace](https://github.com/fallintoplace)) - [`c069622`](npm/cli@c069622) [#9464](npm/cli#9464) show full parent command path in subcommand usage errors ([#9464](npm/cli#9464)) ([@owlstronaut](https://github.com/owlstronaut)) - [`1bb62bb`](npm/cli@1bb62bb) [#9454](npm/cli#9454) config: clarify --all help so it's accurate for approve-scripts and deny-scripts ([@JamieMagee](https://github.com/JamieMagee)) - [`84eeb5f`](npm/cli@84eeb5f) [#9431](npm/cli#9431) audit: don't apply min-release-age before filter when verifying installed signatures ([@JamieMagee](https://github.com/JamieMagee)) - [`3bd3377`](npm/cli@3bd3377) [#9426](npm/cli#9426) block forbidden keys in Queryable setter to prevent prototype pollution ([@12122J](https://github.com/12122J), [@claude](https://github.com/claude)) ##### Documentation - [`a86a7a9`](npm/cli@a86a7a9) [#9522](npm/cli#9522) approve-scripts only throws EGLOBAL when run with -g ([@JamieMagee](https://github.com/JamieMagee)) - [`693bb3d`](npm/cli@693bb3d) [#9508](npm/cli#9508) clarify package.json override value specs ([#9508](npm/cli#9508)) ([@github-actions](https://github.com/github-actions)\[bot], [@ded-furby](https://github.com/ded-furby)) - [`ccffe4a`](npm/cli@ccffe4a) [#9501](npm/cli#9501) use the latest version for global update and outdated's `wanted` ([#9501](npm/cli#9501)) ([@github-actions](https://github.com/github-actions)\[bot], [@liangmiQwQ](https://github.com/liangmiQwQ)) - [`66e97c2`](npm/cli@66e97c2) [#9478](npm/cli#9478) update minimum npm required for npm trust ([@meeech](https://github.com/meeech)) ##### Dependencies - [`bd09b87`](npm/cli@bd09b87) [#9542](npm/cli#9542) `postcss-selector-parser@7.1.4` - [`95bfc4c`](npm/cli@95bfc4c) [#9542](npm/cli#9542) `tinyglobby@0.2.17` - [`8c0d5fd`](npm/cli@8c0d5fd) [#9542](npm/cli#9542) `tar@7.5.16` - [`967d377`](npm/cli@967d377) [#9542](npm/cli#9542) `semver@7.8.4` - [`cdaac1b`](npm/cli@cdaac1b) [#9542](npm/cli#9542) `pacote@21.5.1` - [`25c8a9e`](npm/cli@25c8a9e) [#9542](npm/cli#9542) `node-gyp@12.4.0` ##### Chores - [`2922fa4`](npm/cli@2922fa4) [#9542](npm/cli#9542) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.8.0): `@npmcli/arborist@9.8.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.11.0): `@npmcli/config@10.11.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.10): `libnpmdiff@8.1.10` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.3.0): `libnpmexec@10.3.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.24): `libnpmfund@7.0.24` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.10): `libnpmpack@9.1.10` ##### [v11.16.0](https://github.com/npm/cli/releases/tag/v11.16.0) ##### Features - [`4b67f6e`](npm/cli@4b67f6e) [#9416](npm/cli#9416) publish --access=private alias for restricted ([#9416](npm/cli#9416)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`a10c7ca`](npm/cli@a10c7ca) [#9415](npm/cli#9415) Phase 1 of `allowScripts` opt-in install-script policy ([#9360](npm/cli#9360)) ([#9415](npm/cli#9415)) ([@owlstronaut](https://github.com/owlstronaut), [@JamieMagee](https://github.com/JamieMagee)) ##### Bug Fixes - [`1f7869b`](npm/cli@1f7869b) [#9411](npm/cli#9411) fix typo of fullMetadata ([@owlstronaut](https://github.com/owlstronaut)) - [`cde03ba`](npm/cli@cde03ba) [#9390](npm/cli#9390) config: pause progress spinner during interactive editor spawn ([#9388](npm/cli#9388)) ([@github-actions](https://github.com/github-actions)\[bot], [@Zelys-DFKH](https://github.com/Zelys-DFKH), [@claude](https://github.com/claude)) ##### Documentation - [`c5e9d73`](npm/cli@c5e9d73) [#9390](npm/cli#9390) Document `npm_old_version` and `npm_new_version` environment variables ([#9389](npm/cli#9389)) ([@github-actions](https://github.com/github-actions)\[bot], [@36degrees](https://github.com/36degrees)) ##### Dependencies - [`cdd7bbc`](npm/cli@cdd7bbc) [#9421](npm/cli#9421) `undici@6.26.0` - [`fde87c9`](npm/cli@fde87c9) [#9421](npm/cli#9421) `sigstore@4.1.1` - [`2779793`](npm/cli@2779793) [#9421](npm/cli#9421) `lru-cache@11.5.1` - [`dea702d`](npm/cli@dea702d) [#9421](npm/cli#9421) `@sigstore/verify@3.1.1` - [`4eab03f`](npm/cli@4eab03f) [#9421](npm/cli#9421) `@sigstore/core@3.2.1` - [`74c7323`](npm/cli@74c7323) [#9421](npm/cli#9421) `@npmcli/agent@4.0.2` - [`edc4ab3`](npm/cli@edc4ab3) [#9421](npm/cli#9421) `semver@7.8.1` - [`5f6ce33`](npm/cli@5f6ce33) [#9421](npm/cli#9421) `make-fetch-happen@15.0.6` ##### Chores - [`bd04976`](npm/cli@bd04976) [#9421](npm/cli#9421) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`aeceb23`](npm/cli@aeceb23) [#9407](npm/cli#9407) sanitize newlines in flags table default and type values ([#9407](npm/cli#9407)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.7.0): `@npmcli/arborist@9.7.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.10.0): `@npmcli/config@10.10.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.9): `libnpmdiff@8.1.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.9): `libnpmexec@10.2.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.23): `libnpmfund@7.0.23` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.9): `libnpmpack@9.1.9` - [workspace](https://github.com/npm/cli/releases/tag/libnpmversion-v8.0.4): `libnpmversion@8.0.4` ##### [v11.15.0](https://github.com/npm/cli/releases/tag/v11.15.0) ##### Features - [`0d5d899`](npm/cli@0d5d899) [#9379](npm/cli#9379) npm stage ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`1433740`](npm/cli@1433740) [#9376](npm/cli#9376) add permissions support to trust commands ([#9376](npm/cli#9376)) ([@github-actions](https://github.com/github-actions)\[bot], [@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`8df10f5`](npm/cli@8df10f5) [#9339](npm/cli#9339) add allow-git/allow-file/allow-directory/allow-remote configs ([@owlstronaut](https://github.com/owlstronaut)) ##### Bug Fixes - [`39b625e`](npm/cli@39b625e) [#9381](npm/cli#9381) key stage download --json output by package name ([#9381](npm/cli#9381)) ([@reggi](https://github.com/reggi), [@Copilot](https://github.com/Copilot)) - [`6aa332d`](npm/cli@6aa332d) [#9339](npm/cli#9339) allow min-release-age in npmrc to coexist with --before ([@raazkhnl](https://github.com/raazkhnl)) - [`468550f`](npm/cli@468550f) [#9339](npm/cli#9339) refactor #failureNode, adjust tests and safety ([@owlstronaut](https://github.com/owlstronaut)) - [`cabe249`](npm/cli@cabe249) [#9339](npm/cli#9339) allow-remote=none does not block registry tarballs ([@owlstronaut](https://github.com/owlstronaut)) ##### Dependencies - [`8416a60`](npm/cli@8416a60) [#9383](npm/cli#9383) `socks@2.8.9` - [`5e5a25b`](npm/cli@5e5a25b) [#9383](npm/cli#9383) `lru-cache@11.5.0` - [`a6f9ad2`](npm/cli@a6f9ad2) [#9383](npm/cli#9383) `ip-address@10.2.0` - [`63f8114`](npm/cli@63f8114) [#9383](npm/cli#9383) `brace-expansion@5.0.6` - [`6918b4c`](npm/cli@6918b4c) [#9383](npm/cli#9383) `bin-links@6.0.2` - [`bf84079`](npm/cli@bf84079) [#9383](npm/cli#9383) `tar@7.5.15` - [`bdef82c`](npm/cli@bdef82c) [#9383](npm/cli#9383) `semver@7.8.0` - [`3f38a67`](npm/cli@3f38a67) [#9383](npm/cli#9383) `hosted-git-info@9.0.3` ##### Chores - [`816f3bf`](npm/cli@816f3bf) [#9383](npm/cli#9383) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.6.0): `@npmcli/arborist@9.6.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.1): `@npmcli/config@10.9.1` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.8): `libnpmdiff@8.1.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.8): `libnpmexec@10.2.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.22): `libnpmfund@7.0.22` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.8): `libnpmpack@9.1.8` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v11.2.0): `libnpmpublish@11.2.0` ##### [v11.14.1](https://github.com/npm/cli/releases/tag/v11.14.1) ##### Bug Fixes - [`dca12cb`](npm/cli@dca12cb) [#9328](npm/cli#9328) remove settings ([#9328](npm/cli#9328)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut)) ##### [v11.14.0](https://github.com/npm/cli/releases/tag/v11.14.0) ##### Features - [`45fc5e0`](npm/cli@45fc5e0) [#9288](npm/cli#9288) add allow-directory, allow-file, and allow-remote ([#9288](npm/cli#9288)) ([@github-actions](https://github.com/github-actions)\[bot], [@wraithgar](https://github.com/wraithgar)) ##### Bug Fixes - [`6c17544`](npm/cli@6c17544) [#9318](npm/cli#9318) sbom: dedupe per-node dependsOn / relationships ([#9318](npm/cli#9318)) ([@github-actions](https://github.com/github-actions)\[bot], [@mikaelkristiansson](https://github.com/mikaelkristiansson)) ##### Dependencies - [`840fe18`](npm/cli@840fe18) [#9322](npm/cli#9322) `socks@10.1.1` - [`b771289`](npm/cli@b771289) [#9322](npm/cli#9322) `ip-address@10.1.1` - [`addffcb`](npm/cli@addffcb) [#9322](npm/cli#9322) `cidr-regex@5.0.5` ##### Chores - [`041fd58`](npm/cli@041fd58) [#9322](npm/cli#9322) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`89c505a`](npm/cli@89c505a) [#9320](npm/cli#9320) add cli-triage team as codeowner ([#9320](npm/cli#9320)) ([@github-actions](https://github.com/github-actions)\[bot], [@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.5.0): `@npmcli/arborist@9.5.0` - [workspace](https://github.com/npm/cli/releases/tag/config-v10.9.0): `@npmcli/config@10.9.0` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.7): `libnpmdiff@8.1.7` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.7): `libnpmexec@10.2.7` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.21): `libnpmfund@7.0.21` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.7): `libnpmpack@9.1.7` ##### [v11.13.0](https://github.com/npm/cli/releases/tag/v11.13.0) ##### Features - [`8e8dadb`](npm/cli@8e8dadb) [#9246](npm/cli#9246) add `u` as alias for `update` command ([#9246](npm/cli#9246)) ([@github-actions](https://github.com/github-actions)\[bot], [@Ausoj](https://github.com/Ausoj)) ##### Bug Fixes - [`ecd161b`](npm/cli@ecd161b) [#9258](npm/cli#9258) ignore intended error code ([@owlstronaut](https://github.com/owlstronaut)) ##### Dependencies - [`8d2fdcd`](npm/cli@8d2fdcd) [#9272](npm/cli#9272) `lru-cache@11.3.5` - [`e603d36`](npm/cli@e603d36) [#9272](npm/cli#9272) `node-gyp@12.3.0` - [`d48b7da`](npm/cli@d48b7da) [#9272](npm/cli#9272) `is-cidr@6.0.4` - [`032a5ca`](npm/cli@032a5ca) [#9240](npm/cli#9240) `@sigstore/protobuf-specs@0.5.1` - [`33a81e7`](npm/cli@33a81e7) [#9240](npm/cli#9240) `tinyglobby@0.2.16` - [`68dc4a0`](npm/cli@68dc4a0) [#9240](npm/cli#9240) `picomatch@4.0.4` - [`1bb6703`](npm/cli@1bb6703) [#9240](npm/cli#9240) `lru-cache@11.3.3` - [`37059e4`](npm/cli@37059e4) [#9240](npm/cli#9240) `diff@8.0.4` - [`fb450ab`](npm/cli@fb450ab) [#9240](npm/cli#9240) `minimatch@10.2.5` - [`7c4bbbf`](npm/cli@7c4bbbf) [#9240](npm/cli#9240) `tar@7.5.13` - [`703a3bc`](npm/cli@703a3bc) [#9240](npm/cli#9240) `minipass-flush@1.0.6` ##### Chores - [`e0724ac`](npm/cli@e0724ac) [#9272](npm/cli#9272) dev dependency updates ([@owlstronaut](https://github.com/owlstronaut)) - [`d249341`](npm/cli@d249341) [#9230](https://github.com/npm/cli/pull/9230) don't run npm update in CI ([@owlstronaut](https://github.com/owlstronaut)) - [workspace](https://github.com/npm/cli/releases/tag/arborist-v9.4.3): `@npmcli/arborist@9.4.3` - [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v8.1.6): `libnpmdiff@8.1.6` - [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v10.2.6): `libnpmexec@10.2.6` - [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v7.0.20): `libnpmfund@7.0.20` - [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v9.1.6): `libnpmpack@9.1.6`
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #9882 to
release/v11.