Open
Conversation
3a87d67 to
3cfecb6
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
3cfecb6 to
eeb39a0
Compare
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^6.14.18->^10.2.0Release Notes
npm/cli (npm)
v10.2.0Compare Source
Features
7c459d2#6801 add npm sbom command (#6801) (@bdehamer)81a460f#6732 add package-lock-only mode to npm query (@wraithgar)0d29855#6732 add no-package-lock mode to npm audit (@wraithgar)Bug Fixes
2207628#6823 use strip-ansi module instead of internal regex (#6823) (@wraithgar)d46d052#6798 tolerate null bugs URLs (#6798) (@vladh)fb1b674#6758 deprecate: ignore implicit workspace mode (#6758) (@wraithgar)Documentation
68031f2#6844 updateCONTRIBUTING.mdto prevent errors (#6844) (@darcyclarke)3ac703c#6831 addincludeparam to commands that haveomitparam (#6831) (@siemhesda)03912db#6819 add init-specific params to init docs/help (#6819) (@wraithgar)8088325#6800 Update npm-doctor.md (#6800) (@siemhesda)Dependencies
aa6728b#6859tar@6.2.0ce9089f#6859npm-package-arg@11.0.139d7f04#6859minipass@7.0.40a47af5#6859hosted-git-info@7.0.1af93130#6859glob@10.3.103ebc474#6859@npmcli/query@3.0.1284cbfd#6858@npmcli/agent@2.2.0@npmcli/arborist@7.2.0@npmcli/config@8.0.0libnpmaccess@8.0.1libnpmdiff@6.0.2libnpmexec@7.0.2libnpmfund@5.0.0libnpmorg@6.0.1libnpmpack@6.0.2libnpmpublish@9.0.1v10.1.0Compare Source
Features
1c93c44#6755 Add--cpuand--osoption to override platform specific install (#6755) (@yukukotani)Bug Fixes
7bf2374#6762 make$npm_execpathalways point to npm (@rotu)Documentation
09d8e0a#6759 fix versions of node.js in readme (#6759) (@JoaoOtavioS)Dependencies
f76066a#6771@npmcli/agent@2.1.1@npmcli/arborist@7.1.0@npmcli/config@7.2.0libnpmdiff@6.0.1libnpmexec@7.0.1libnpmfund@4.1.1libnpmpack@6.0.1v10.0.0Compare Source
Features
48a7b07remove prerelease flags (@lukekarrys)Dependencies
@npmcli/arborist@7.0.0@npmcli/config@7.1.0libnpmaccess@8.0.0libnpmdiff@6.0.0libnpmexec@7.0.0libnpmfund@4.1.0libnpmhook@10.0.0libnpmorg@6.0.0libnpmpack@6.0.0libnpmpublish@9.0.0libnpmsearch@7.0.0libnpmteam@6.0.0libnpmversion@5.0.0v9.8.1Compare Source
Bug Fixes
38351c9#6651 warn on autocorrected package.json entries during publish (@wraithgar)02c7ddb#6642 much clearer npx 'canceled' error (#6642) (@rahulio96, @AaronHamilton965)Documentation
36bf5fe#6643 Added steps for using npm/npx locally to CONTRIBUTING.md (#6643) (@AaronHamilton965, @rahulio96)Dependencies
a0763d3#6651@npmcli/package-json@4.0.124f5a8b#6653supports-color@9.4.0f45498b#6653chalk@5.3.044d60eb#6653minimatch@9.0.3fc9a843#6653bin-links@3.0.2daad9ad#6653semver@7.5.4c1ffd6a#6653 move @npmcli/fs, @npmcli/promise-spawn into dependencieslibnpmexec@6.0.3v9.8.0Compare Source
Features
67459e7#6626 addpkg fixsubcommand (@wraithgar)89b2741#6548 add ps1 scripts (#6548) (@mribbons, @lukekarrys)Dependencies
b252164#6626@npmcli/package-json@4.0.09238682#6623sigstore@1.7.0(#6623)@npmcli/arborist@6.3.0libnpmdiff@5.0.19libnpmexec@6.0.2libnpmfund@4.0.19libnpmpack@5.0.19libnpmpublish@7.5.0v9.7.2Compare Source
Bug Fixes
939a188#6574 ignore node prereleases in npm engines check (#6574) (@wraithgar)d980405#6556 better color support detection (#6556) (@lukekarrys)40d7e09#6555 remove unnecessary package.json values (#6555) (@lukekarrys)3a7378d#6554 cleanup bin contents (@lukekarrys)e722439#6497 move all definitions to @npmcli/config package (@lukekarrys)Documentation
405ffbf#6557 remove redundant statement about files attribute (#6557) (@DaviDevMod)cd1e6aa#6551 add flagpackage-lock-onlyfornpm install(#6551) (@m4rch3n1ng)Dependencies
aebc523#6585safe-buffer@5.2.1string_decoder@1.3.0(#6585)bb6054b#6573tuf-js@1.1.7aee4a30#6573strip-ansi@7.1.06105dbc#6573path-scurry@1.9.222d44e8#6573read-package-json@6.0.4fdd02fd#6573jackspeak@2.2.17797075#6573is-core-module@2.12.1f9780cc#6573sigstore@1.6.072d6a79#6573semver@7.5.298f1f5f#6573nopt@7.2.08710ff8#6573pacote@15.2.00cb539d#6573node-gyp@9.4.039ad586#6573ini@4.1.15e0070c#6573glob@10.2.7minimatch@9.0.126cf235#6573cacache@17.1.3@npmcli/arborist@6.2.10@npmcli/config@6.2.1libnpmdiff@5.0.18libnpmexec@6.0.1libnpmfund@4.0.18libnpmpack@5.0.18libnpmpublish@7.4.0v9.7.1Compare Source
Dependencies
7467ff6#6518@npmcli/package-json@3.1.1,@npmcli/git@4.1.0v9.7.0Compare Source
Features
a63a6d8#6490 add provenanceFile option for libnpmpublish (@bdehamer)2a8f4f2#6490 add new exclusive config item publish-file (@wraithgar)361e194#6483 implement flag --prefer-dedupe fornpm install(#6483) (@m4rch3n1ng)Bug Fixes
38eb39b#6514 strip ansi characters from search results (#6514) (@wraithgar)4b5ccfc#6477 make usage and completion static functions (#6477) (@lukekarrys)4f39e8c#6479 refactor engines validation to lint syntax (#6479) (@lukekarrys)f3cfe12#6482 remove unused lib/npm relics (#6482) (@lukekarrys)87de0c7#6472 move explore command to @npmcli/package-json (@wraithgar)636e29e#6472 move to @npmcli/package-json where possible (@wraithgar)37cc797#6418 retrieve registry keys via TUF (#6418) (@bdehamer)Documentation
83cd5bd#6480 add global option for uninstall (#6480) (@m4rch3n1ng)0400ce3#6481 add cli params tonpm set,npm get(#6481) (@m4rch3n1ng)c3638ce#6468 removepackage-lockoption fornpm ci(#6468) (@m4rch3n1ng)Dependencies
060d587chalk@5.2.0,npm-audit-report@5.0.0fc52ca8#6472 remove read-package-json-fast3238aa7#6472 remove read-package-json@npmcli/config@6.2.0libnpmexec@6.0.0libnpmpublish@7.3.0v9.6.7Compare Source
Bug Fixes
9202c7d#6464 npm cache completion (#6464) (@m4rch3n1ng)6ce99a8#6461 exit codes in node v20 (#6461) (@MichaelBitard)23c865f#6434 deprecate ci-name config (#6434) (@wraithgar)Documentation
7751dd4#6413 add a comma (#6413) (@darryltec)Dependencies
afc38a5#6458cacache@17.1.2afb936c#6458tuf-js@1.1.6f6a0884#6458readable-stream@4.4.0858f0ca#6458postcss-selector-parser@6.0.1353ecb84#6458path-scurry@1.9.1d93f70c#6458signal-exit@4.0.219214b5#6458@npmcli/package-json@3.1.0f53e6ff#6458sigstore@1.5.294d6ee7#6458glob@10.2.4902cb80#6458semver@7.5.135e2e9a#6458@npmcli/run-script@6.0.2@npmcli/config@6.1.7libnpmpublish@7.2.0v9.6.6Compare Source
Dependencies
70e65b1#6423tuf-js@1.1.5(#6423)72291f7#6416read-package-json@6.0.3e498f82#6416minimatch@9.0.013aa7b7#6416minipass@5.0.0f2a5678#6416tar@6.1.1469d4dd2#6416 npm updateabdca39#6416sigstore@1.4.016f68fb#6416glob@10.2.267fcfb1#6416ignore-walk@6.0.3bfa2ff3#6416make-fetch-happen@11.1.1877591a#6416npm-registry-fetch@14.0.57630517#6416pacote@15.1.3c2d6e0a#6416write-file-atomic@5.0.1acdf97e#6416which@3.0.100c541a#6416ssri@10.0.41b95e73#6416read-package-json@6.0.26927fd3#6416fs-minipass@3.0.23eec56e#6416cacache@17.1.07a2ce3f#6416@npmcli/run-script@6.0.13881770#6416@npmcli/map-workspaces@3.0.4@npmcli/arborist@6.2.9libnpmdiff@5.0.17libnpmexec@5.0.17libnpmfund@4.0.17libnpmorg@5.0.4libnpmpack@5.0.17libnpmpublish@7.1.4v9.6.5Compare Source
Bug Fixes
33dc428#6374 account for npx package-name with no spec (@wraithgar)82879f6#6225 lazy loading of arborist and pacote (#6225) (@wraithgar)f4e73ab#6322 remove incompatible params from ci (#6322) (@wraithgar)c7fe1c7#6328 save raw data to file, not parsed data (@wraithgar)Documentation
31214a6#6381 Update description for publish --provenance flag (#6381) (@feelepxyz)997bcdf#6329 fix npm cache folder location for windows (#6329) (@charlie-wong)Dependencies
fae5e00#6372sigstore@1.3.0(#6372)3fa9542#6363semver@7.5.0e49844e#6363minipass-fetch@3.0.2357cc29#6363walk-up-path@3.0.12c80b1e#6363ini@4.1.05933841#6363minipass@4.2.8b39d54e#6363minimatch@7.4.6201aa5a#6363ssri@10.0.3acb9120#6363read@2.1.02472205#6363npm-registry-fetch@14.0.42780714#6363npm-install-checks@6.1.1b5af015#6363make-fetch-happen@11.1.014c498d#6363@npmcli/metavuln-calculator@5.0.1@npmcli/arborist@6.2.8@npmcli/config@6.1.6libnpmdiff@5.0.16libnpmexec@5.0.16libnpmfund@4.0.16libnpmpack@5.0.16v9.6.4Compare Source
Documentation
54795a3#6312 filter archives out of version manager search (#6312) (@ljharb)530c285#6306 remove reference to npm-packlist (#6306) (@staff0rd)Dependencies
85935ac#6325ssri@10.0.2(#6325)f1388b4#6317 npm update7dd0129#6317glob@9.3.2deca335#6317promise-call-limit@1.0.2@npmcli/arborist@6.2.7libnpmdiff@5.0.15libnpmexec@5.0.15libnpmfund@4.0.15libnpmpack@5.0.15v9.6.3Compare Source
Bug Fixes
829503b#6304 don't break up log message across lines (@wraithgar)1435fcf#6304 do less work loading ./lib/npm.js (@wraithgar)09b58e4#6284 make all color output use an npm instance of chalk (#6284) (@lukekarrys)e252532#6283 do less work looking up commands (#6283) (@wraithgar)6a4bcba#6275 clean up man sorting (@wraithgar)8a96b65#6275 ignore ts and map files (@wraithgar)94d2b39#6271 Do not log warnings about log cleanup when logs_max=0 (#6271) (@jmealo)2def359#6277 updated ebadplatform messaging to be generated based on the error (#6277) (@nlf)Documentation
1e2eb81#6311 replace version manager list with a github search (#6311) (@wraithgar)9d2be4e#6289 remove npm bin link (#6289) (@KevinRouchut)Dependencies
e652dbd#6308minimatch@7.4.3(#6308)01986d1#6307sigstore@1.2.0(#6307)ea12627#6275minimatch@7.4.2ec3e020#6275glob@9.3.1952fbed#6275read-package-json@6.0.1dd43d30#6275parse-conflict-json@3.0.1d5ce7ca#6275npm-install-checks@6.1.0704cd1e#6275nopt@7.1.0a6da22a#6275ignore-walk@6.0.255955fd#6275cacache@17.0.5839b670#6275@npmcli/map-workspaces@3.0.39a7b8e8#6275@npmcli/git@4.0.457c0a55#6275 npm update74c80f5#6275minipass@4.2.5b174c90#6275graceful-fs@4.2.11@npmcli/arborist@6.2.6@npmcli/config@6.1.5libnpmdiff@5.0.14libnpmexec@5.0.14libnpmfund@4.0.14libnpmpack@5.0.14libnpmpublish@7.1.3v9.6.2Compare Source
Bug Fixes
4622b42#6247 add provenance publish notice (#6247) (@bdehamer)Dependencies
434b461#6255sigstore@1.1.1(#6255)@npmcli/config@6.1.4libnpmpublish@7.1.2v9.6.1Compare Source
Bug Fixes
e455e3f#6211 send options with grant/revoke requests (#6211) (@DavidTanner)e4de224#6220 clean uri from audit error (#6220) (@wraithgar)Dependencies
cb45b21#6231 npm update1f60a7e#6231minipass@4.2.4@npmcli/arborist@6.2.5libnpmdiff@5.0.13libnpmexec@5.0.13libnpmfund@4.0.13libnpmpack@5.0.13libnpmpublish@7.1.1v9.6.0Compare Source
Features
84fbaf2#6216 add preliminary fish shell completion (@wraithgar)Bug Fixes
c4c8754audit: add signatures to completion (@wraithgar)fc46489access: only complete once (@wraithgar)b43961acmd-list: alias only to real commands (@wraithgar)Documentation
2695e1f#6187 npm v9 creates package-lock.json v3 (#6187) (@tuukka)Dependencies
71ae406#6218@npmcli/installed-package-contents@2.0.2@npmcli/arborist@6.2.4libnpmdiff@5.0.12libnpmexec@5.0.12libnpmfund@4.0.12libnpmpack@5.0.12v9.5.1Compare Source
Documentation
9bc455b#6188 fixing typos (#6188) (@deining)ec8c95c#6186 update OSI link (#6186) (@roerohan)Dependencies
7ba3e17#6189 npm updatef7a5200pacote@15.1.1@npmcli/arborist@6.2.3libnpmdiff@5.0.11libnpmexec@5.0.11libnpmfund@4.0.11libnpmpack@5.0.11v9.5.0Compare Source
Features
79bfd03#6153 audit signatures verifies attestations (@feelepxyz)5fc6473add provenance attestation (@bdehamer)Bug Fixes
53f75a4#6158 gracefully fallback from auth-type=web (#6158) (@MylesBorins)ed59aae#6162 refactor error reporting in audit command (@bdehamer)Dependencies
fad0473minipass@4.0.3678c6bfminimatch@6.2.09b4b366ci-info@3.8.0d20ee2apacote@15.1.0libnpmpublish@7.1.0libnpmteam@5.0.3v9.4.2Compare Source
Bug Fixes
d02da52#6142 revertinstall-linksdefault back tofalse(#6142) (@nlf)Documentation
6ea2cd7#6134 update references to OTP to be accurate (#6134) (@MylesBorins)Dependencies
cb6713d#6143 rebuild package-lock (#6143)8200f4f#6133ignore-walk@6.0.1d43f881map-workspaces@3.0.299457f1minimatch@6.1.6f4c8c62init-package-json@5.0.03c6615fnpm-user-validate@2.0.010445caremove mkdirpab82492node-gyp@9.3.174c5cbbminipass@4.0.21138038make-fetch-happen@11.0.3c1ccfa1glob@8.1.03dc17cefs-minipass@3.0.15c84a99ci-info@3.7.1fc5332fread@2.0.0@npmcli/arborist@6.2.2@npmcli/config@6.1.3libnpmdiff@5.0.10libnpmexec@5.0.10libnpmfund@4.0.10libnpmhook@9.0.3libnpmorg@5.0.3libnpmpack@5.0.10libnpmpublish@7.0.8v9.4.1Compare Source
Bug Fixes
1525a5e#6082 unpublish with scoped registry (@wraithgar)Dependencies
721fe3f#6118read-package-json-fast@3.0.26e4a649pacote@15.0.81820afecacache@17.0.424b2ec4@npmcli/promise-spawn@6.0.24b8046e@npmcli/name-from-folder@2.0.01d4be7a@npmcli/map-workspaces@3.0.1a39556f@npmcli/template-oss@4.11.364b06ed#6115http-cache-semantics@4.1.1@npmcli/arborist@6.2.1@npmcli/config@6.1.2libnpmaccess@7.0.2libnpmdiff@5.0.9libnpmexec@5.0.9libnpmfund@4.0.9libnpmhook@9.0.2libnpmorg@5.0.2Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.