chore(deps): update npm to v11 #203
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>= 6.14.18->>= 11.5.2Release Notes
npm/cli (npm)
v11.5.2Compare Source
Bug Fixes
7d900c4#8467 oidc visibility check for provenance (#8467) (@reggi, @wraithgar)Documentation
d4e56b2#8459 update snapshot generation command (#8459) (@MikeMcC399)v11.5.1Compare Source
Bug Fixes
476bf17#8457 provenance should only default for oidc (@reggi)v11.5.0Compare Source
Features
1cce318#8336 adds support for oidc publish (#8336) (@reggi)Bug Fixes
7f66f0a#8447 add better hint forbeforeand clean up description (@wraithgar)280817a#8447 add --before param to command help output (@wraithgar)6e47325#8441 Makes 404 errors less scary without revealing existence (#8441) (@owlstronaut)0a97ffd#8429 handle signal exits gracefully (@owlstronaut)5b858c6#8411 ensure progress bars display consistently across all environments (#8411) (@owlstronaut)Documentation
ef3529e#8435 add test snapshot (#8435) (@reggi, @wraithgar)b7758d7#8418 remove reference to Node.js download less common os (#8418) (@MikeMcC399)746ac5d#8380 remove duplicate info (#8380) (@alexsch01)4673e9c#8371 rebrand OS X references to macOS (@MikeMcC399)Dependencies
398fed4#8450normalize-package-data@7.0.15b242c9#8450validate-npm-package-name@6.0.2d4e8a8a#8450tuf-js@3.1.0e1b37b2#8450picomatch@4.0.33cb5884#8450socks@2.8.6daea981#8450ci-info@4.3.039ad47d#8450aproba@2.1.0a789f33#8450agent-base@7.1.41c0d257#8450@npmcli/metavuln-calculator@9.0.1Chores
804a964#8450 update devDependencies in lockfile (@wraithgar)643ae71#8450 update mock-registry to use local arborist (@wraithgar)cf023d7#8421 contributing: prepare easier copy-paste contributing commands (#8421) (@MikeMcC399)3f60b5f#8383@npmcli/template-oss@4.24.4(#8383) (@wraithgar)01f8cc6#8381@npmcli/template-oss@4.24.3(#8381) (@wraithgar)@npmcli/arborist@9.1.3@npmcli/config@10.3.1libnpmdiff@8.0.6libnpmexec@10.1.5libnpmfund@7.0.6libnpmpack@9.0.6libnpmpublish@11.1.0v11.4.2Compare Source
Bug Fixes
f2d6947#8345 move warning to new line whennpm initis canceled (@mbtools)e758dd7#8318 powershell: multiple Invoke-Expression fixes (#8318) (@alexsch01)Documentation
7233cb3#8355 remove deprecated section related temp files (#8355) (@milaninfy)fb7a498#8351 clarify shell used for script (#8351) (@milaninfy)8b55d38#8329 Rename "command" to "script" (#8329) (@DanKaplanSES)Dependencies
7b05420#8358fdir@6.4.6e1a3b23#8358tinyglobby@0.2.14522efa2#8358socks@2.8.57a0723f#8358debug@4.4.19a342a4#8358brace-expansion@2.0.2e691ba0#8358@sigstore/protobuf-specs@0.4.342ef765#8358validate-npm-package-name@6.0.1774c0b1#8358@npmcli/redact@3.2.2dda6f87#8317@npmcli/package-json@6.2.0bc08ac7#8317 remove normalize-package-dataChores
0ad1444#8358 dev dependency updates (@wraithgar)@npmcli/arborist@9.1.2libnpmdiff@8.0.5libnpmexec@10.1.4libnpmfund@7.0.5libnpmpack@9.0.5libnpmpublish@11.0.1v11.4.1Compare Source
Documentation
3ed764a#8308 Clarify script working directory behavior (fixes #8305) (#8308) (@tarekwfa0110, @owlstronaut)Chores
2f30251#8314 remove references to skimdb.npmjs.com (#8314) (@shmam)9cb9d50#8298 add contributor to changelog entry (#8298) (@wraithgar)Dependencies
@npmcli/arborist@9.1.1libnpmdiff@8.0.4libnpmexec@10.1.3libnpmfund@7.0.4libnpmpack@9.0.4v11.4.0Compare Source
Features
a0e60fb#8246 added init-private option (@owlstronaut)57aa89f#8265 use run by default and run-script as the alias (#8265) (@owlstronaut)0d4c023#8234 install: add package info to json output (#8234) (@wraithgar)Bug Fixes
8794fd9#8297 powershell: support pipeline input with Invoke-Expression (#8297) (@alexsch01)b5173d1#8293 docs: corrected github_path (#8293) (@xaos7991)2210d7a#8278 powershell: use Invoke-Expression to pass args (#8278) (@alexsch01, @mbtools)8669d09#8228 add otplease for enable-2fa, disable-2fa, access (#8228) (@reggi, @wraithgar)78b5a6f#8269 correctly handle scenario where prefix is the cwd (#8269) (@owlstronaut, @ficocelliguy)fdc3413#8221 exec: Fails to Execute Binaries Named After Shell Keywords (#8221) (@13sfaith)4b08e2e#8245 docs: prepare script runs for local package links (@milaninfy)1622ac4#8241 handle missingtimein packument to prevent crash onnpm view(@owlstronaut)db8f5da#8110 outdated: add dependent location in long output (#8110) (@milaninfy, @wraithgar)Documentation
d2498df#8295 RemoveCHANGELOGfrom never-ignored list (#8295) (@mrazauskas)4d5c3c1#8283 fixoverridesexample in package-json.md (#8283) (@glasser)96cc4f9#8226 format publish as code to highlight it (@LiangYingC)4990ea0#8226 clarify legacy token creation in npm login and adduser commands (@LiangYingC)Dependencies
c97ef8a#8246init-package-json@8.2.1f48613d#8292@sigstore/verify@2.1.1a4c5e74#8292tinyglobby@0.2.13b9156d2#8292http-cache-semantics@4.2.0472a685#8292binary-extensions@3.1.0988696e#8292@sigstore/tuf@3.1.1569ac84#8292semver@7.7.22521c9b#8233@sigstore/protobuf-specs@0.4.13274d68#8233@npmcli/query@4.0.1c263626#8233abbrev@3.0.178df711#8233hosted-git-info@8.1.0Chores
e80e38e#8292 dev dependency updates (@wraithgar)3231ee9#8244 update snapshots (@owlstronaut)c561a33#8233 dev dependency updates (@owlstronaut)7eca19c#8215 update workflow permissions for updating Node PR (@owlstronaut)@npmcli/arborist@9.1.0@npmcli/config@10.3.0libnpmaccess@10.0.1libnpmdiff@8.0.3libnpmexec@10.1.2libnpmfund@7.0.3libnpmpack@9.0.3libnpmteam@8.0.1libnpmversion@8.0.1v11.3.0Compare Source
Features
b306d25#8129 addnode-gypas actual config (@wraithgar)Bug Fixes
2f5392a#8135 makenpm runautocomplete work with workspaces (#8135) (@terrainvidia)Documentation
26b6454fix grammer in local path note (@cgay)1c0e83d#7886 fix typo in package-json.md (#7886) (@stoneLeaf)14efa57#8178 fix example package name inoverridesexplainer (#8178) (@G-Rath)4183cba#8162 logging: replace proceeding with preceding in loglevels details (#8162) (@tyleralbee)Dependencies
e57f112#8207minipass-fetch@4.0.13daabb1#8207minizlib@3.0.2c7a7527#8207ci-info@4.2.020b09b6#8207node-gyp@11.2.0679bc4a#8129@npmcli/run-script@9.1.0Chores
3fbed84#8207 install rimraf as a devdependency for smoke tests (@owlstronaut)43f0b41#8207 dev dependency updates (@wraithgar)26803bc#8147 release integration node 23 yml (#8147) (@reggi)d679a1a#8146 release integration node 23 (#8146) (@reggi)@npmcli/arborist@9.0.2@npmcli/config@10.2.0libnpmdiff@8.0.2libnpmexec@10.1.1libnpmfund@7.0.2libnpmpack@9.0.2v11.2.0Compare Source
Features
b306d25#8129 addnode-gypas actual config (@wraithgar)Bug Fixes
2f5392a#8135 makenpm runautocomplete work with workspaces (#8135) (@terrainvidia)Documentation
26b6454fix grammer in local path note (@cgay)1c0e83d#7886 fix typo in package-json.md (#7886) (@stoneLeaf)14efa57#8178 fix example package name inoverridesexplainer (#8178) (@G-Rath)4183cba#8162 logging: replace proceeding with preceding in loglevels details (#8162) (@tyleralbee)Dependencies
e57f112#8207minipass-fetch@4.0.13daabb1#8207minizlib@3.0.2c7a7527#8207ci-info@4.2.020b09b6#8207node-gyp@11.2.0679bc4a#8129@npmcli/run-script@9.1.0Chores
3fbed84#8207 install rimraf as a devdependency for smoke tests (@owlstronaut)43f0b41#8207 dev dependency updates (@wraithgar)26803bc#8147 release integration node 23 yml (#8147) (@reggi)d679a1a#8146 release integration node 23 (#8146) (@reggi)@npmcli/arborist@9.0.2@npmcli/config@10.2.0libnpmdiff@8.0.2libnpmexec@10.1.1libnpmfund@7.0.2libnpmpack@9.0.2v11.1.0Compare Source
Features
1cce318#8336 adds support for oidc publish (#8336) (@reggi)Bug Fixes
7f66f0a#8447 add better hint forbeforeand clean up description (@wraithgar)280817a#8447 add --before param to command help output (@wraithgar)6e47325#8441 Makes 404 errors less scary without revealing existence (#8441) (@owlstronaut)0a97ffd#8429 handle signal exits gracefully (@owlstronaut)5b858c6#8411 ensure progress bars display consistently across all environments (#8411) (@owlstronaut)Documentation
ef3529e#8435 add test snapshot (#8435) (@reggi, @wraithgar)b7758d7#8418 remove reference to Node.js download less common os (#8418) (@MikeMcC399)746ac5d#8380 remove duplicate info (#8380) (@alexsch01)4673e9c#8371 rebrand OS X references to macOS (@MikeMcC399)Dependencies
398fed4#8450normalize-package-data@7.0.15b242c9#8450validate-npm-package-name@6.0.2d4e8a8a#8450tuf-js@3.1.0e1b37b2#8450picomatch@4.0.33cb5884#8450socks@2.8.6daea981#8450ci-info@4.3.039ad47d#8450aproba@2.1.0a789f33#8450agent-base@7.1.41c0d257#8450@npmcli/metavuln-calculator@9.0.1Chores
804a964#8450 update devDependencies in lockfile (@wraithgar)643ae71#8450 update mock-registry to use local arborist (@wraithgar)cf023d7#8421 contributing: prepare easier copy-paste contributing commands (#8421) (@MikeMcC399)3f60b5f#8383@npmcli/template-oss@4.24.4(#8383) (@wraithgar)01f8cc6#8381@npmcli/template-oss@4.24.3(#8381) (@wraithgar)@npmcli/arborist@9.1.3@npmcli/config@10.3.1libnpmdiff@8.0.6libnpmexec@10.1.5libnpmfund@7.0.6libnpmpack@9.0.6libnpmpublish@11.1.0v11.0.0Compare Source
Documentation
8a911da#7963 ls: removed design change pending section note (#7963) (@milaninfy)Dependencies
5319e48#7973 remove unnecessary sprintf-js files in node_modules (#7973)d369c77#7976socks-proxy-agent@8.0.53b2951a#7976https-proxy-agent@7.0.6a598b7b#7976agent-base@7.1.352bcaf6#7976debug@4.4.0aabf345#7976p-map@7.0.328e8761#7976npm-package-arg@12.0.1Chores
ecd7190#7976 dev dependency updates (@wraithgar)a07f4e0#7976@npmcli/template-oss@4.23.6(@wraithgar)687ab12#7970 remove pre-release mode from npm 11 and workspaces (#7970) (@wraithgar)@npmcli/arborist@9.0.0@npmcli/config@10.0.0libnpmaccess@10.0.0libnpmdiff@8.0.0libnpmexec@10.0.0libnpmfund@7.0.0libnpmorg@8.0.0libnpmpack@9.0.0libnpmpublish@11.0.0libnpmsearch@9.0.0libnpmteam@8.0.0libnpmversion@8.0.0v10.9.3Compare Source
Bug Fixes
7cff878#8343 powershell: use Invoke-Expression to pass args (#8343) (@alexsch01)78dc057#8378 stop working around bug fixed innpm-package-arg@12.0.2(@TrevorBurnham)e510f14#8248 docs: 'pacakge' -> 'package' (#8248) (@t3hmrman)Dependencies
c38ec84#8378validate-npm-package-name@6.0.172564c5#8378spdx-license-ids@3.0.2120fa199#8378socks@2.8.548c193a#8378socks-proxy-agent@8.0.500fccfb#8378semver@7.7.25ab8aac#8378read@4.1.0224c69e#8378p-map@7.0.31e41678#8378npm-package-arg@12.0.2e9cf30e#8378nopt@8.1.02bedf25#8378minizlib@3.0.2a795ee0#8378minipass-fetch@4.0.18ed043c#8378https-proxy-agent@7.0.674518d0#8378http-cache-semantics@4.2.0cc7dcfc#8378hosted-git-info@8.1.013aea40#8378foreground-child@3.3.19c81599#8378exponential-backoff@3.1.2b59097f#8378node-gyp@11.2.08b29435#8378debug@4.4.14c8e170#8378cidr-regex@4.1.39bb94a3#8378is-cidr@5.1.1a1dbb0b#8378ci-info@4.2.00a5f2ff#8378chalk@5.4.17912c9c#8378brace-expansion@2.0.219028b8#8378agent-base@7.1.3fd26776#8378abbrev@3.0.1dbb23ab#8378sigstore@3.1.092feb9b#8378@sigstore/protobuf-specs@0.4.34fd7174#8378@sigstore/tuf@3.1.1b327bc2#8378@npmcli/run-script@9.1.004e7e1c#8378@npmcli/redact@3.2.2.90d2aab#8378@npmcli/query@4.0.12e47537#8378@npmcli/package-json@6.2.0a5eb5dd#8378@npmcli/git@6.0.3Chores
15e545b#8384@npmcli/template-oss@4.24.4(#8384) (@wraithgar)fb5a9f2#8378@npmcli/template-oss@4.24.3(@wraithgar)19da79a#8378 dev dependency updates (@wraithgar)@npmcli/arborist@8.0.1libnpmdiff@7.0.1libnpmexec@9.0.1libnpmfund@6.0.1libnpmpack@8.0.1v10.9.2Compare Source
Dependencies
ae9345e#7959@npmcli/run-script@9.0.239a19b3#7959node-gyp@11.0.093e2186#7956@npmcli/map-workspaces@4.0.2bf0ea00#7956@npmcli/package-json@6.1.0c84baa3#7956init-package-json@7.0.2e642099#7956node-gyp@10.3.1v10.9.1Compare Source
Bug Fixes
c7fe0db#7924 perf: enable compile cache if present (#7924) (@H4ad)Dependencies
a221db7#7931npm-install-checks@7.1.1fbad17a#7931hosted-git-info@8.0.265d2a86#7922@sigstore/tuf@3.0.0be45963#7922sigstore@3.0.0fb0bfbd#7922spdx-license-ids@3.0.20ccadf2a](https://redirect.github.com/npm/cli/commit/ccadf2aa519e5de5d6b9ff62beConfiguration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.