Repository navigation
v2.5.1
Fixed
-
npm no longer reads a flag's value as the package name. npm was the last
of the five ecosystems still failing open on an unrecognised flag: the scan
skipped anything starting-and took the next bare token, so
npm exec --loglevel silly server-aand… server-bboth resolved to
silly. Because 2.4.0's identity gate treats a matching name as a positive
confirmation, two unrelated servers collapsed into one identity and one was
served the other's cached tool descriptions.--registry,--global false
and--color alwayscollided the same way.npm's flag arity is now generated from npm's own config schema
(@npmcli/config'sdefinitionsandshorthands, 181 flags and 40
shorthands) rather than transcribed by hand, and an unlisted flag makes the
scan report no identity instead of guessing. Shorthands are expanded from
npm's own map, sonpm --silent exec <pkg>keeps resolving and the previous
hand-coded-yspecial case is retired. Two flags whose arity depends on the
next token's content —--colorand--browser— are deliberately
unlisted and therefore refused.The cost, deliberately: a server launched with a flag npm's own schema
does not describe can no longer be auto-updated.gateway.update_server
refuses it by name and command line rather than probing. An omission costs
auto-update for one unusual config — visible, and fixable by adding the flag
— where the previous "take the next token" default produced a silent
collision instead. No bundled manifest server is affected: all 98 launchable
entries resolve exactly as before.Two places where the boolean rule is subtler than "a switch takes no value":
nullis a real published npm package. npm's parser consumes a literal
nullafter only the five nullable booleans (--yes,--optional,
--production,--workspaces,--expect-results); after any other
boolean,nullis the package. The rule is scoped to those five, so
npm exec --global null pkg-aand… pkg-bstay distinct.npxbehaves the opposite way tonpm. It pre-scans its arguments and
inserts--before the first positional, so a boolean switch there consumes
nothing — verified against the real binary:npx --global true pkgruns the
packagetrue. Because the--no-family differs again,npxreports no
identity for these forms rather than a modelled guess.
Known remaining gap, tracked in
#195: the same class
survives in rarer spellings — an attached value (--global=pkg), nopt's
abbreviation matching (-n,--y), andnpx's own rewriting of-p=and
removal of-n. No server in the bundled manifest uses any of them.