Skip to content

docs: document npm 12 install script blocking - #9838

Merged
reggi merged 1 commit into
latestfrom
reggi/docs-npm12-allow-scripts-changelog
Aug 3, 2026
Merged

docs: document npm 12 install script blocking#9838
reggi merged 1 commit into
latestfrom
reggi/docs-npm12-allow-scripts-changelog

Conversation

@reggi

@reggi reggi commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Summary

Add the omitted npm 12 breaking-change note explaining that dependency lifecycle scripts are blocked by default unless covered by allowScripts, including the approval and rebuild workflow.

Cause

The change was introduced in 5cd5150. Although its message described a v12-only default flip, it used feat: instead of feat!: and did not include a BREAKING CHANGE: footer. Release Please therefore classified it as a regular feature and omitted it from the aggregated npm 12 breaking-change notes.

Release notes

The published v12.0.0 GitHub release was corrected manually with the same breaking-change entry. This PR corrects the source-controlled changelog used by the npm documentation site.

Manual correction process

If a breaking change is omitted from release notes in the future:

  1. Do not rewrite the merged commit. Add the missing entry under the released version’s ⚠️ BREAKING CHANGES section in the root CHANGELOG.md and submit a documentation PR.

  2. After the PR merges, the npm documentation repository’s scheduled Update CLI workflow copies the root changelog into the corresponding CLI documentation page and publishes it. Dispatch that workflow manually if the docs need to update immediately.

  3. Update the existing GitHub release separately because a changelog PR cannot modify an already-published release. Preserve the complete current release body before editing it because gh release edit --notes-file replaces the entire body:

    gh release view <tag> --repo npm/cli --json body --jq .body > release.md
    # Add the same breaking-change entry to release.md.
    gh release edit <tag> --repo npm/cli --notes-file release.md
  4. Verify that the source changelog, npm documentation page, and GitHub release contain identical wording.

To prevent the omission, breaking commits must use a conventional-commit breaking marker such as feat!: and include a BREAKING CHANGE: footer describing the user-visible impact.

Fixes #9750

Add the omitted breaking-change note explaining that dependency lifecycle scripts are blocked by default and how to approve and run them.\n\nFixes #9750\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f1b70f0a-a8ab-42ae-9f8a-5188817ce956
@reggi
reggi requested review from a team as code owners August 3, 2026 15:58
@reggi
reggi merged commit bea9066 into latest Aug 3, 2026
28 checks passed
@reggi
reggi deleted the reggi/docs-npm12-allow-scripts-changelog branch August 3, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[DOCS] Missing mention of breaking change lifecycle script block in npm@12.0.0 release notes

2 participants