Skip to content

v2.5.1

Choose a tag to compare

@github-actions github-actions released this 26 Aug 21:27
· 106 commits to main since this release
v2.5.1
ea8333c

Fixed

  • npm no longer reads a flag's value as the package name. npm was the last
    of the five ecosystems still failing open on an unrecognised flag: the scan
    skipped anything starting - and took the next bare token, so
    npm exec --loglevel silly server-a and … server-b both resolved to
    silly. Because 2.4.0's identity gate treats a matching name as a positive
    confirmation
    , two unrelated servers collapsed into one identity and one was
    served the other's cached tool descriptions. --registry, --global false
    and --color always collided the same way.

    npm's flag arity is now generated from npm's own config schema
    (@npmcli/config's definitions and shorthands, 181 flags and 40
    shorthands) rather than transcribed by hand, and an unlisted flag makes the
    scan report no identity instead of guessing. Shorthands are expanded from
    npm's own map, so npm --silent exec <pkg> keeps resolving and the previous
    hand-coded -y special case is retired. Two flags whose arity depends on the
    next token's content — --color and --browser — are deliberately
    unlisted and therefore refused.

    The cost, deliberately: a server launched with a flag npm's own schema
    does not describe can no longer be auto-updated. gateway.update_server
    refuses it by name and command line rather than probing. An omission costs
    auto-update for one unusual config — visible, and fixable by adding the flag
    — where the previous "take the next token" default produced a silent
    collision instead. No bundled manifest server is affected: all 98 launchable
    entries resolve exactly as before.

    Two places where the boolean rule is subtler than "a switch takes no value":

    • null is a real published npm package. npm's parser consumes a literal
      null after only the five nullable booleans (--yes, --optional,
      --production, --workspaces, --expect-results); after any other
      boolean, null is the package. The rule is scoped to those five, so
      npm exec --global null pkg-a and … pkg-b stay distinct.
    • npx behaves the opposite way to npm. It pre-scans its arguments and
      inserts -- before the first positional, so a boolean switch there consumes
      nothing — verified against the real binary: npx --global true pkg runs the
      package true. Because the --no- family differs again, npx reports no
      identity for these forms rather than a modelled guess.

    Known remaining gap, tracked in
    #195: the same class
    survives in rarer spellings — an attached value (--global=pkg), nopt's
    abbreviation matching (-n, --y), and npx's own rewriting of -p= and
    removal of -n. No server in the bundled manifest uses any of them.