chore(deps): update dependency npm to v11#187
Open
dev-mend-for-github-com[bot] wants to merge 1 commit intoelectron-upgradefrom
Open
chore(deps): update dependency npm to v11#187dev-mend-for-github-com[bot] wants to merge 1 commit intoelectron-upgradefrom
dev-mend-for-github-com[bot] wants to merge 1 commit intoelectron-upgradefrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
8.19.2→11.6.3By merging this PR, the below vulnerabilities will be automatically resolved:
Release Notes
npm/cli (npm)
v11.6.3Compare Source
Bug Fixes
c6242d9#8706 change npm profile to create tokens with GAT support (#8706) (@owlstronaut, @wraithgar)cbc6fa9#8731 order of version information in error message (#8731) (@piotrd, @pd-be)11dbd7e#8709 display full token when creating authentication tokens (#8709) (@MaxBlack-dev, Max Black)49a4eef#8676 use look behind regex for trailing slash stripping (#8676) (@wraithgar)b1aee62#8645 dep flag calculation (#8645) (@liamcmitchell)Documentation
ca53c21#8745 add workspace usage examples (#8745) (@MaxBlack-dev, Max Black)e71ca0e#8746 add --save flag to documentation (#8746) (@MaxBlack-dev, Max Black)06510a8#8683 add ignore-scripts option to npm version help and docs (#8683) (@Tejas242)Dependencies
7f72238#8723cacache@20.0.27ac9db8#8723init-package-json@8.2.341e97c6#8723validate-npm-package-name@7.0.06b1fbe1#8723npm-package-arg@13.0.2aa1d486#8723@npmcli/promise-spawn@9.0.1599c819#8723which@6.0.0e49286e#8723ini@5.0.0b7c9f96#8723@npmcli/promise-spawn@9.0.08cc9f70#8723ssri@13.0.00b7274f#8723pacote@21.0.459b3c6a#8723@npmcli/redact@4.0.0578abad#8723node-gyp@12.1.089c4151#8723@npmcli/git@7.0.1c6d109d#8723make-fetch-happen@15.0.334d8599#8723npm-registry-fetch@19.1.14811a86#8723@npmcli/run-script@10.0.36cb77df#8723@npmcli/installed-package-contents@4.0.005ac7a7#8723proc-log@6.0.00a74f6d#8723bin-links@6.0.0c02ce5c#8723@npmcli/package-json@7.0.29c0cefa#8723json-parse-even-better-errors@5.0.0041b9b2#8723parse-conflict-json@5.0.1a1b0fea#8723@npmcli/name-from-folder@4.0.0a085745#8723abbrev@4.0.000d9c7d#8723nopt@9.0.03404dca#8723npm-install-checks@8.0.0542fcf3#8723@npmcli/node-gyp@5.0.089e14d3#8723tar@7.5.25383f3a#8723npm-registry-fetch@19.1.01bb9a7d#8723npm-profile@12.0.1de619a4#8723npm-pick-manifest@11.0.30e042ec#8723npm-packlist@10.0.32a3c338#8723node-gyp@11.5.0b96e86c#8723minimatch@10.1.1d347329#8723exponential-backoff@3.1.3d6830f4#8723@npmcli/run-script@10.0.2bcc7ec8#8723@npmcli/metavuln-calculator@9.0.37a419df#8723@npmcli/map-workspaces@5.0.1Chores
32bdd83#8723 fix package-lock (@wraithgar)4bff14b#8670 write tarball to testDir (#8670) (@wraithgar)679486b#8672 fix lockfile (#8672) (@wraithgar)@npmcli/arborist@9.1.7@npmcli/config@10.4.3libnpmdiff@8.0.10libnpmexec@10.1.9libnpmfund@7.0.10libnpmpack@9.0.10libnpmpublish@11.1.3libnpmversion@8.0.3v11.6.2Compare Source
Bug Fixes
c54d1e9#8633 progress bar code cleanup (#8633) (@wraithgar)d352e27#8629 do not redact notice logs going to stdout (#8629) (@wraithgar)5ac3678#8617 spelling in ./lib and ./test/lib (#8617) (@jsoref)9197995#8619 spelling (#8619) (@jsoref)dd884e3#8618 spelling (#8618) (@jsoref)f6028e6#8614 skip redacting urls meant for opening by the user (#8614) (@wraithgar, @jolyndenning)54fd27f#8602 refactor node.ideallyInert to node.inert (#8602) (@liamcmitchell)79e3c1e#8593 use @npmcli/package-json to normalize package data (@wraithgar)Documentation
0469c5e#8639 rewrap markdown (#8639) (@jsoref)9ceb9c1#8636 rewrap markdown (#8636) (@jsoref)6324370#8616 fix spelling (#8616) (@jsoref)1b0429a#8607 Fix spelling (#8607) (@jsoref)7fbe07a#8603 clean up deprecatednpm accesscommands (#8603) (@jsoref)Dependencies
fa7cc6f#8662ci-info@4.3.1(#8662)b05461b#8663@sigstore/sign@4.0.1(#8663)c31de22#8661 downgrade ci-info to 4.3.0 (#8661) (@wraithgar)c5191b5#8659ci-info@4.3.1f255c92#8659hosted-git-info@9.0.2bdaf323#8659is-cidr@6.0.1a33f106#8659lru-cache@11.2.28044e07#8659npm-package-arg@13.0.1f577504#8659npm-packlist@10.0.29aa4fa6#8659semver@7.7.3fe9484a#8593 remove normalize-package-dataChores
b3409f4#8659 dev dependency updates (@wraithgar)e8de81b#8643 Add automatically generated annotation to dependencies.md (#8643) (@jsoref)67cfaf3#8627 fix spelling: different (#8627) (@jsoref)17ddc0d#8622 fix spelling (#8622) (@jsoref)c3e1790#8605 Remove reference to nonexistent calendar (#8605) (@jsoref)ac9143e#8604 Improve link accessibility for screen reader users (#8604) (@jsoref)62d73e7#8601 remove references to benchmarks workflow (#8601) (@jsoref)bb4b739#8598 remove stale comment (#8598) (@jsoref)f73e65d#8592 fix build url code for remark-github@12 (#8592) (@wraithgar)@npmcli/arborist@9.1.6@npmcli/config@10.4.2libnpmaccess@10.0.3libnpmdiff@8.0.9libnpmexec@10.1.8libnpmfund@7.0.9libnpmpack@9.0.9libnpmpublish@11.1.2v11.6.1Compare Source
Bug Fixes
d389614#8579 corrects peer dependency flag propagation (@owlstronaut)5db81c3#8512 allow concurrent non-local npx calls (#8512) (@jenseng, @wraithgar)Documentation
7a09902#8582 bring back certfile (#8582) (@jenseng)Dependencies
849dcb6#8589tar@7.5.1(#8589)ea15731#8576binary-extensions@3.1.00f41bac#8576tiny-relative-date@2.0.207bf540#8576is-cidr@6.0.0ef87ec6#8576diff@8.0.248285e0#8576 add fdir, isexe, and picomatch to node_modules099238a#8576fdir@6.5.06e4d673#8576isexe@3.1.109a7494#8576supports-color@10.2.2c5157c9#8576chalk@5.6.246035db#8576debug@4.4.35f6664b#8576spdx-license-ids@3.0.225516583#8576socks@2.8.76a392f3#8576tinyglobby@0.2.159519f18#8576npm-install-checks@7.1.234bafd1#8576node-gyp@11.4.2dfd034e#8576@npmcli/promise-spawn@8.0.3d4eef14#8576rimraf@6.0.1566f1b7#8576minimatch@10.0.3ac33497#8576mkdirp@3.0.11676626#8576glob@11.0.3817f0b1#8576ignore-walk@8.0.079a4e67#8576minizlib@3.0.238fa2c2#8576negotiator@1.0.024252a1#8576@npmcli/agent@4.0.0ea7ca5f#8576lru-cache@11.2.1521823b#8576@npmcli/git@7.0.0bf6b686#8576npm-package-arg@13.0.09392488#8576npm-package-manifest@11.0.10082083#8576normalize-package-data@8.0.0633c4ed#8576hosted-git-info@9.0.066f64eb#8576make-fetch-happen@15.0.21f85f94#8576@sigstore/tuf@4.0.0a2bdecc#8576sigstore@4.0.01149971#8576npm-registry-fetch@19.0.0b5bd5e3#8576npm-profile@12.0.06221e27#8576@npmcli/metavuln-calculator@9.0.2da81a37#8576cacache@20.0.16b4c5f9#8576@npmcli/run-script@10.0.0cb36a8a#8576init-package-json@8.2.2b6bb9ae#8576pacote@21.0.31b4433f#8576@npmcli/map-workspaces@5.0.0ceae674#8576@npmcli/package-json@7.0.14f37534#8576 remove read-package-json-fastChores
7eb5c09#8576 update package-lock with peer flag fixes (@wraithgar)0d00fd8#8576jsdom@27.0.0(@wraithgar)420a569#8576unified@11.0.5(@wraithgar)064deb3#8576remark-rehype@11.1.2(@wraithgar)30fe3ba#8576remark-man@9.0.0(@wraithgar)1c6bb4c#8576rehype-stringify@10.0.1(@wraithgar)208cb93#8576remark-gfm@4.0.1(@wraithgar)4a46b5a#8576remark-github@12.0.0(@wraithgar)93d190b#8576remark-parse@11.0.0(@wraithgar)05301a4#8576remark@15.0.1(@wraithgar)6afdda9#8576ajv-formats@3.0.1(@wraithgar)402a0ab#8576@npmcli/template-oss@4.25.1(@wraithgar)3b43bf7#8576 dev dependency updates (@wraithgar)9f9146f#8576@tufjs/repo-mock@4.0.0(@wraithgar)eed8a10#8576 use latest/local arborist in mock-registry (@wraithgar)@npmcli/arborist@9.1.5@npmcli/config@10.4.1libnpmaccess@10.0.2libnpmdiff@8.0.8libnpmexec@10.1.7libnpmfund@7.0.8libnpmorg@8.0.1libnpmpack@9.0.8libnpmpublish@11.1.1libnpmsearch@9.0.1libnpmteam@8.0.2libnpmversion@8.0.2v11.6.0Compare Source
Features
bdcc10d#8359 add support for optional env var replacements in .npmrc (#8359) (@aczekajski, @owlstronaut)Bug Fixes
dd4cee9#8539 powershell: improve argument parsing (#8539) (@alexsch01)5f18557#8532 powershell: fix issue with modified InvocationName (#8532) (@alexsch01)9e5abf1#8529 add redaction to log format egress (#8529) (@wraithgar)75ce64a#8524 revert handle signal exits gracefully (#8524) (@owlstronaut)5d82d0b#8469 ps1 scripts in powershell 5.1 (#8469) (@splatteredbits)Dependencies
@npmcli/arborist@9.1.4@npmcli/config@10.4.0libnpmdiff@8.0.7libnpmexec@10.1.6libnpmfund@7.0.7libnpmpack@9.0.7v11.5.2Compare Source
Bug Fixes
7d900c4#8467 oidc visibility check for provenance (#8467) (@reggi, @wraithgar)Documentation
d4e56b2#8459 update snapshot generation command (#8459) (@MikeMcC399)v11.5.1Compare Source
Bug Fixes
476bf17#8457 provenance should only default for oidc (@reggi)v11.5.0Compare Source
Bug Fixes
c6242d9#8706 change npm profile to create tokens with GAT support (#8706) (@owlstronaut, @wraithgar)cbc6fa9#8731 order of version information in error message (#8731) (@piotrd, @pd-be)11dbd7e#8709 display full token when creating authentication tokens (#8709) (@MaxBlack-dev, Max Black)49a4eef#8676 use look behind regex for trailing slash stripping (#8676) (@wraithgar)b1aee62#8645 dep flag calculation (#8645) (@liamcmitchell)Documentation
ca53c21#8745 add workspace usage examples (#8745) (@MaxBlack-dev, Max Black)e71ca0e#8746 add --save flag to documentation (#8746) (@MaxBlack-dev, Max Black)06510a8#8683 add ignore-scripts option to npm version help and docs (#8683) (@Tejas242)Dependencies
7f72238#8723cacache@20.0.27ac9db8#8723init-package-json@8.2.341e97c6#8723validate-npm-package-name@7.0.06b1fbe1#8723npm-package-arg@13.0.2aa1d486#8723@npmcli/promise-spawn@9.0.1599c819#8723which@6.0.0e49286e#8723ini@5.0.0b7c9f96#8723@npmcli/promise-spawn@9.0.08cc9f70#8723ssri@13.0.00b7274f#8723pacote@21.0.459b3c6a#8723@npmcli/redact@4.0.0578abad#8723node-gyp@12.1.089c4151#8723@npmcli/git@7.0.1c6d109d#8723make-fetch-happen@15.0.334d8599#8723npm-registry-fetch@19.1.14811a86#8723@npmcli/run-script@10.0.36cb77df#8723@npmcli/installed-package-contents@4.0.005ac7a7#8723proc-log@6.0.00a74f6d#8723bin-links@6.0.0c02ce5c#8723@npmcli/package-json@7.0.29c0cefa#8723json-parse-even-better-errors@5.0.0041b9b2#8723parse-conflict-json@5.0.1a1b0fea#8723@npmcli/name-from-folder@4.0.0a085745#8723abbrev@4.0.000d9c7d#8723nopt@9.0.03404dca#8723npm-install-checks@8.0.0542fcf3#8723@npmcli/node-gyp@5.0.089e14d3#8723tar@7.5.25383f3a#8723npm-registry-fetch@19.1.01bb9a7d#8723npm-profile@12.0.1de619a4#8723npm-pick-manifest@11.0.30e042ec#8723npm-packlist@10.0.32a3c338#8723node-gyp@11.5.0b96e86c#8723minimatch@10.1.1d347329#8723exponential-backoff@3.1.3d6830f4#8723@npmcli/run-script@10.0.2bcc7ec8#8723@npmcli/metavuln-calculator@9.0.37a419df#8723@npmcli/map-workspaces@5.0.1Chores
32bdd83#8723 fix package-lock (@wraithgar)4bff14b#8670 write tarball to testDir (#8670) (@wraithgar)679486b#8672 fix lockfile (#8672) (@wraithgar)@npmcli/arborist@9.1.7@npmcli/config@10.4.3libnpmdiff@8.0.10libnpmexec@10.1.9libnpmfund@7.0.10libnpmpack@9.0.10libnpmpublish@11.1.3libnpmversion@8.0.3v11.4.2Compare Source
Bug Fixes
d389614#8579 corrects peer dependency flag propagation (@owlstronaut)5db81c3#8512 allow concurrent non-local npx calls (#8512) (@jenseng, @wraithgar)Documentation
7a09902#8582 bring back certfile (#8582) (@jenseng)Dependencies
849dcb6#8589tar@7.5.1(#8589)ea15731#8576binary-extensions@3.1.00f41bac#8576tiny-relative-date@2.0.207bf540#8576is-cidr@6.0.0ef87ec6#8576diff@8.0.248285e0#8576 add fdir, isexe, and picomatch to node_modules099238a#8576fdir@6.5.06e4d673#8576isexe@3.1.109a7494#8576supports-color@10.2.2c5157c9#8576chalk@5.6.246035db#8576debug@4.4.35f6664b#8576spdx-license-ids@3.0.225516583#8576socks@2.8.76a392f3#8576tinyglobby@0.2.159519f18[#857