From 0c92c8bca10a7e6f58a5ca01b804274d594eb247 Mon Sep 17 00:00:00 2001
From: npm CLI robot
Date: Thu, 24 Sep 2026 18:28:22 +0000
Subject: [PATCH] deps: upgrade npm to 11.20.0
---
deps/npm/docs/content/commands/npm-ci.md | 2 +-
deps/npm/docs/content/commands/npm-exec.md | 2 +-
.../content/commands/npm-install-ci-test.md | 2 +-
.../docs/content/commands/npm-install-test.md | 2 +-
deps/npm/docs/content/commands/npm-install.md | 2 +-
deps/npm/docs/content/commands/npm-ls.md | 2 +-
deps/npm/docs/content/commands/npm-publish.md | 6 +
deps/npm/docs/content/commands/npm-rebuild.md | 2 +-
deps/npm/docs/content/commands/npm-stage.md | 2 +-
deps/npm/docs/content/commands/npm-token.md | 7 +-
deps/npm/docs/content/commands/npm-update.md | 2 +-
deps/npm/docs/content/commands/npm.md | 2 +-
deps/npm/docs/content/using-npm/config.md | 15 +-
deps/npm/docs/output/commands/npm-access.html | 4 +-
.../npm/docs/output/commands/npm-adduser.html | 4 +-
.../output/commands/npm-approve-scripts.html | 4 +-
deps/npm/docs/output/commands/npm-audit.html | 4 +-
deps/npm/docs/output/commands/npm-bugs.html | 4 +-
deps/npm/docs/output/commands/npm-cache.html | 4 +-
deps/npm/docs/output/commands/npm-ci.html | 5 +-
.../docs/output/commands/npm-completion.html | 4 +-
deps/npm/docs/output/commands/npm-config.html | 4 +-
deps/npm/docs/output/commands/npm-dedupe.html | 4 +-
.../output/commands/npm-deny-scripts.html | 4 +-
.../docs/output/commands/npm-deprecate.html | 4 +-
deps/npm/docs/output/commands/npm-diff.html | 4 +-
.../docs/output/commands/npm-dist-tag.html | 4 +-
deps/npm/docs/output/commands/npm-docs.html | 4 +-
deps/npm/docs/output/commands/npm-doctor.html | 4 +-
deps/npm/docs/output/commands/npm-edit.html | 4 +-
deps/npm/docs/output/commands/npm-exec.html | 5 +-
.../npm/docs/output/commands/npm-explain.html | 4 +-
.../npm/docs/output/commands/npm-explore.html | 4 +-
.../docs/output/commands/npm-find-dupes.html | 4 +-
deps/npm/docs/output/commands/npm-fund.html | 4 +-
deps/npm/docs/output/commands/npm-get.html | 4 +-
.../docs/output/commands/npm-help-search.html | 4 +-
deps/npm/docs/output/commands/npm-help.html | 4 +-
deps/npm/docs/output/commands/npm-init.html | 4 +-
.../output/commands/npm-install-ci-test.html | 5 +-
.../output/commands/npm-install-scripts.html | 4 +-
.../output/commands/npm-install-test.html | 5 +-
.../npm/docs/output/commands/npm-install.html | 5 +-
deps/npm/docs/output/commands/npm-link.html | 4 +-
deps/npm/docs/output/commands/npm-ll.html | 4 +-
deps/npm/docs/output/commands/npm-login.html | 4 +-
deps/npm/docs/output/commands/npm-logout.html | 4 +-
deps/npm/docs/output/commands/npm-ls.html | 6 +-
deps/npm/docs/output/commands/npm-org.html | 4 +-
.../docs/output/commands/npm-outdated.html | 4 +-
deps/npm/docs/output/commands/npm-owner.html | 4 +-
deps/npm/docs/output/commands/npm-pack.html | 4 +-
deps/npm/docs/output/commands/npm-ping.html | 4 +-
deps/npm/docs/output/commands/npm-pkg.html | 4 +-
deps/npm/docs/output/commands/npm-prefix.html | 4 +-
.../npm/docs/output/commands/npm-profile.html | 4 +-
deps/npm/docs/output/commands/npm-prune.html | 4 +-
.../npm/docs/output/commands/npm-publish.html | 8 +-
deps/npm/docs/output/commands/npm-query.html | 4 +-
.../npm/docs/output/commands/npm-rebuild.html | 5 +-
deps/npm/docs/output/commands/npm-repo.html | 4 +-
.../npm/docs/output/commands/npm-restart.html | 4 +-
deps/npm/docs/output/commands/npm-root.html | 4 +-
deps/npm/docs/output/commands/npm-run.html | 4 +-
deps/npm/docs/output/commands/npm-sbom.html | 4 +-
deps/npm/docs/output/commands/npm-search.html | 4 +-
deps/npm/docs/output/commands/npm-set.html | 4 +-
.../docs/output/commands/npm-shrinkwrap.html | 4 +-
deps/npm/docs/output/commands/npm-stage.html | 6 +-
deps/npm/docs/output/commands/npm-star.html | 4 +-
deps/npm/docs/output/commands/npm-stars.html | 4 +-
deps/npm/docs/output/commands/npm-start.html | 4 +-
deps/npm/docs/output/commands/npm-stop.html | 4 +-
deps/npm/docs/output/commands/npm-team.html | 4 +-
deps/npm/docs/output/commands/npm-test.html | 4 +-
deps/npm/docs/output/commands/npm-token.html | 11 +-
deps/npm/docs/output/commands/npm-trust.html | 4 +-
.../docs/output/commands/npm-undeprecate.html | 4 +-
.../docs/output/commands/npm-uninstall.html | 4 +-
.../docs/output/commands/npm-unpublish.html | 4 +-
deps/npm/docs/output/commands/npm-unstar.html | 4 +-
deps/npm/docs/output/commands/npm-update.html | 5 +-
.../npm/docs/output/commands/npm-version.html | 4 +-
deps/npm/docs/output/commands/npm-view.html | 4 +-
deps/npm/docs/output/commands/npm-whoami.html | 4 +-
deps/npm/docs/output/commands/npm.html | 6 +-
deps/npm/docs/output/commands/npx.html | 4 +-
.../docs/output/configuring-npm/folders.html | 4 +-
.../docs/output/configuring-npm/install.html | 4 +-
.../output/configuring-npm/npm-global.html | 4 +-
.../docs/output/configuring-npm/npm-json.html | 4 +-
.../configuring-npm/npm-shrinkwrap-json.html | 4 +-
.../docs/output/configuring-npm/npmrc.html | 4 +-
.../output/configuring-npm/package-json.html | 4 +-
.../configuring-npm/package-lock-json.html | 4 +-
deps/npm/docs/output/using-npm/config.html | 16 +-
.../using-npm/dependency-selectors.html | 4 +-
.../npm/docs/output/using-npm/developers.html | 4 +-
deps/npm/docs/output/using-npm/logging.html | 4 +-
deps/npm/docs/output/using-npm/orgs.html | 4 +-
.../docs/output/using-npm/package-spec.html | 4 +-
deps/npm/docs/output/using-npm/registry.html | 4 +-
deps/npm/docs/output/using-npm/removal.html | 4 +-
deps/npm/docs/output/using-npm/scope.html | 4 +-
deps/npm/docs/output/using-npm/scripts.html | 4 +-
.../npm/docs/output/using-npm/workspaces.html | 4 +-
deps/npm/lib/commands/token.js | 19 ++
deps/npm/lib/utils/allow-scripts-writer.js | 4 +-
deps/npm/lib/utils/key-values.js | 14 +-
deps/npm/lib/utils/oidc.js | 6 +-
deps/npm/lib/utils/reify-output.js | 5 +-
deps/npm/man/man1/npm-access.1 | 2 +-
deps/npm/man/man1/npm-adduser.1 | 2 +-
deps/npm/man/man1/npm-approve-scripts.1 | 2 +-
deps/npm/man/man1/npm-audit.1 | 2 +-
deps/npm/man/man1/npm-bugs.1 | 2 +-
deps/npm/man/man1/npm-cache.1 | 2 +-
deps/npm/man/man1/npm-ci.1 | 4 +-
deps/npm/man/man1/npm-completion.1 | 2 +-
deps/npm/man/man1/npm-config.1 | 2 +-
deps/npm/man/man1/npm-dedupe.1 | 2 +-
deps/npm/man/man1/npm-deny-scripts.1 | 2 +-
deps/npm/man/man1/npm-deprecate.1 | 2 +-
deps/npm/man/man1/npm-diff.1 | 2 +-
deps/npm/man/man1/npm-dist-tag.1 | 2 +-
deps/npm/man/man1/npm-docs.1 | 2 +-
deps/npm/man/man1/npm-doctor.1 | 2 +-
deps/npm/man/man1/npm-edit.1 | 2 +-
deps/npm/man/man1/npm-exec.1 | 4 +-
deps/npm/man/man1/npm-explain.1 | 2 +-
deps/npm/man/man1/npm-explore.1 | 2 +-
deps/npm/man/man1/npm-find-dupes.1 | 2 +-
deps/npm/man/man1/npm-fund.1 | 2 +-
deps/npm/man/man1/npm-get.1 | 2 +-
deps/npm/man/man1/npm-help-search.1 | 2 +-
deps/npm/man/man1/npm-help.1 | 2 +-
deps/npm/man/man1/npm-init.1 | 2 +-
deps/npm/man/man1/npm-install-ci-test.1 | 4 +-
deps/npm/man/man1/npm-install-scripts.1 | 2 +-
deps/npm/man/man1/npm-install-test.1 | 4 +-
deps/npm/man/man1/npm-install.1 | 4 +-
deps/npm/man/man1/npm-link.1 | 2 +-
deps/npm/man/man1/npm-ll.1 | 2 +-
deps/npm/man/man1/npm-login.1 | 2 +-
deps/npm/man/man1/npm-logout.1 | 2 +-
deps/npm/man/man1/npm-ls.1 | 4 +-
deps/npm/man/man1/npm-org.1 | 2 +-
deps/npm/man/man1/npm-outdated.1 | 2 +-
deps/npm/man/man1/npm-owner.1 | 2 +-
deps/npm/man/man1/npm-pack.1 | 2 +-
deps/npm/man/man1/npm-ping.1 | 2 +-
deps/npm/man/man1/npm-pkg.1 | 2 +-
deps/npm/man/man1/npm-prefix.1 | 2 +-
deps/npm/man/man1/npm-profile.1 | 2 +-
deps/npm/man/man1/npm-prune.1 | 2 +-
deps/npm/man/man1/npm-publish.1 | 6 +-
deps/npm/man/man1/npm-query.1 | 2 +-
deps/npm/man/man1/npm-rebuild.1 | 4 +-
deps/npm/man/man1/npm-repo.1 | 2 +-
deps/npm/man/man1/npm-restart.1 | 2 +-
deps/npm/man/man1/npm-root.1 | 2 +-
deps/npm/man/man1/npm-run.1 | 2 +-
deps/npm/man/man1/npm-sbom.1 | 2 +-
deps/npm/man/man1/npm-search.1 | 2 +-
deps/npm/man/man1/npm-set.1 | 2 +-
deps/npm/man/man1/npm-shrinkwrap.1 | 2 +-
deps/npm/man/man1/npm-stage.1 | 4 +-
deps/npm/man/man1/npm-star.1 | 2 +-
deps/npm/man/man1/npm-stars.1 | 2 +-
deps/npm/man/man1/npm-start.1 | 2 +-
deps/npm/man/man1/npm-stop.1 | 2 +-
deps/npm/man/man1/npm-team.1 | 2 +-
deps/npm/man/man1/npm-test.1 | 2 +-
deps/npm/man/man1/npm-token.1 | 6 +-
deps/npm/man/man1/npm-trust.1 | 2 +-
deps/npm/man/man1/npm-undeprecate.1 | 2 +-
deps/npm/man/man1/npm-uninstall.1 | 2 +-
deps/npm/man/man1/npm-unpublish.1 | 2 +-
deps/npm/man/man1/npm-unstar.1 | 2 +-
deps/npm/man/man1/npm-update.1 | 4 +-
deps/npm/man/man1/npm-version.1 | 2 +-
deps/npm/man/man1/npm-view.1 | 2 +-
deps/npm/man/man1/npm-whoami.1 | 2 +-
deps/npm/man/man1/npm.1 | 4 +-
deps/npm/man/man1/npx.1 | 2 +-
deps/npm/man/man5/folders.5 | 2 +-
deps/npm/man/man5/install.5 | 2 +-
deps/npm/man/man5/npm-global.5 | 2 +-
deps/npm/man/man5/npm-json.5 | 2 +-
deps/npm/man/man5/npm-shrinkwrap-json.5 | 2 +-
deps/npm/man/man5/npmrc.5 | 2 +-
deps/npm/man/man5/package-json.5 | 2 +-
deps/npm/man/man5/package-lock-json.5 | 2 +-
deps/npm/man/man7/config.7 | 12 +-
deps/npm/man/man7/dependency-selectors.7 | 2 +-
deps/npm/man/man7/developers.7 | 2 +-
deps/npm/man/man7/logging.7 | 2 +-
deps/npm/man/man7/orgs.7 | 2 +-
deps/npm/man/man7/package-spec.7 | 2 +-
deps/npm/man/man7/registry.7 | 2 +-
deps/npm/man/man7/removal.7 | 2 +-
deps/npm/man/man7/scope.7 | 2 +-
deps/npm/man/man7/scripts.7 | 2 +-
deps/npm/man/man7/workspaces.7 | 2 +-
.../arborist/lib/arborist/build-ideal-tree.js | 26 ++
.../@npmcli/arborist/lib/script-allowed.js | 12 +-
.../@npmcli/arborist/package.json | 2 +-
.../config/lib/definitions/definitions.js | 14 +-
.../node_modules/@npmcli/config/package.json | 2 +-
deps/npm/node_modules/libnpmdiff/package.json | 4 +-
deps/npm/node_modules/libnpmexec/package.json | 4 +-
deps/npm/node_modules/libnpmfund/package.json | 4 +-
deps/npm/node_modules/libnpmpack/package.json | 4 +-
deps/npm/node_modules/libnpmpublish/README.md | 8 +-
.../node_modules/libnpmpublish/lib/publish.js | 6 +
.../node_modules/libnpmpublish/package.json | 2 +-
deps/npm/package.json | 16 +-
.../tap-snapshots/test/lib/docs.js.test.cjs | 17 +-
deps/npm/test/fixtures/mock-oidc.js | 7 +-
deps/npm/test/lib/commands/pack.js | 10 +-
deps/npm/test/lib/commands/publish.js | 252 ++++++++++++++++++
deps/npm/test/lib/commands/stage/list.js | 7 +
deps/npm/test/lib/commands/stage/view.js | 3 +
deps/npm/test/lib/commands/token.js | 112 ++++++++
deps/npm/test/lib/commands/uninstall.js | 28 ++
.../npm/test/lib/utils/allow-scripts-prune.js | 21 ++
.../test/lib/utils/allow-scripts-writer.js | 41 +++
deps/npm/test/lib/utils/key-values.js | 34 +++
deps/npm/test/lib/utils/reify-output.js | 76 ++++++
.../test/lib/utils/resolve-allow-scripts.js | 16 ++
230 files changed, 1105 insertions(+), 351 deletions(-)
diff --git a/deps/npm/docs/content/commands/npm-ci.md b/deps/npm/docs/content/commands/npm-ci.md
index 741caf5eae70..8cf6a42690b3 100644
--- a/deps/npm/docs/content/commands/npm-ci.md
+++ b/deps/npm/docs/content/commands/npm-ci.md
@@ -290,7 +290,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-exec.md b/deps/npm/docs/content/commands/npm-exec.md
index ff08d07786a8..87be6dbfd672 100644
--- a/deps/npm/docs/content/commands/npm-exec.md
+++ b/deps/npm/docs/content/commands/npm-exec.md
@@ -178,7 +178,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-install-ci-test.md b/deps/npm/docs/content/commands/npm-install-ci-test.md
index 2194a4df84a8..667748635734 100644
--- a/deps/npm/docs/content/commands/npm-install-ci-test.md
+++ b/deps/npm/docs/content/commands/npm-install-ci-test.md
@@ -243,7 +243,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-install-test.md b/deps/npm/docs/content/commands/npm-install-test.md
index e13f79a51e6f..4311f80279d9 100644
--- a/deps/npm/docs/content/commands/npm-install-test.md
+++ b/deps/npm/docs/content/commands/npm-install-test.md
@@ -320,7 +320,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-install.md b/deps/npm/docs/content/commands/npm-install.md
index 98d69d5e8424..efc07bc7598f 100644
--- a/deps/npm/docs/content/commands/npm-install.md
+++ b/deps/npm/docs/content/commands/npm-install.md
@@ -662,7 +662,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-ls.md b/deps/npm/docs/content/commands/npm-ls.md
index b38603c203fc..e3be39fcf040 100644
--- a/deps/npm/docs/content/commands/npm-ls.md
+++ b/deps/npm/docs/content/commands/npm-ls.md
@@ -23,7 +23,7 @@ Note that nested packages will *also* show the paths to the specified packages.
For example, running `npm ls promzard` in npm's source tree will show:
```bash
-npm@11.19.1 /path/to/npm
+npm@11.20.0 /path/to/npm
└─┬ init-package-json@0.0.4
└── promzard@0.1.5
```
diff --git a/deps/npm/docs/content/commands/npm-publish.md b/deps/npm/docs/content/commands/npm-publish.md
index 04c020b3563f..f0999657fc05 100644
--- a/deps/npm/docs/content/commands/npm-publish.md
+++ b/deps/npm/docs/content/commands/npm-publish.md
@@ -222,6 +222,9 @@ This value is not exported to the environment for child processes.
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the `provenance-file` config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
+
This config cannot be used with: `provenance-file`
#### `provenance-file`
@@ -231,6 +234,9 @@ This config cannot be used with: `provenance-file`
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
+
This config cannot be used with: `provenance`
### See Also
diff --git a/deps/npm/docs/content/commands/npm-rebuild.md b/deps/npm/docs/content/commands/npm-rebuild.md
index c70307a2a7fe..6b3095ff9d17 100644
--- a/deps/npm/docs/content/commands/npm-rebuild.md
+++ b/deps/npm/docs/content/commands/npm-rebuild.md
@@ -120,7 +120,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-stage.md b/deps/npm/docs/content/commands/npm-stage.md
index 798d6c2d953a..4228a43cce77 100644
--- a/deps/npm/docs/content/commands/npm-stage.md
+++ b/deps/npm/docs/content/commands/npm-stage.md
@@ -158,7 +158,7 @@ npm stage publish
| `--workspace`, `-w` | | String (can be set multiple times) | Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the `workspace` config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the `npm init` command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. |
| `--workspaces` | null | null or Boolean | Set to true to run the command in the context of **all** configured workspaces. Explicitly setting this to false will cause commands like `install` to ignore workspaces altogether. When not set explicitly: - Commands that operate on the `node_modules` tree (install, update, etc.) will link workspaces into the `node_modules` folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, _unless_ one or more workspaces are specified in the `workspace` config. |
| `--include-workspace-root` | false | Boolean | Include the workspace root when workspaces are enabled for a command. When false, specifying individual workspaces via the `workspace` config, or all workspaces via the `workspaces` flag, will cause npm to operate only on the specified workspaces, and not on the root project. |
-| `--provenance` | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. |
+| `--provenance` | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. When the `provenance-file` config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped. |
### `npm stage list`
diff --git a/deps/npm/docs/content/commands/npm-token.md b/deps/npm/docs/content/commands/npm-token.md
index 3c8e08d7fc38..45e9347f9d04 100644
--- a/deps/npm/docs/content/commands/npm-token.md
+++ b/deps/npm/docs/content/commands/npm-token.md
@@ -110,11 +110,14 @@ the token access to specific organizations.
#### `packages-and-scopes-permission`
* Default: null
-* Type: null, "read-only", "read-write", or "no-access"
+* Type: null, "read-only", "read-write", "read-write-stage-only", or
+ "no-access"
When creating a Granular Access Token with `npm token create`, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
diff --git a/deps/npm/docs/content/commands/npm-update.md b/deps/npm/docs/content/commands/npm-update.md
index 317f85f7d0db..6da8ef5ac0e2 100644
--- a/deps/npm/docs/content/commands/npm-update.md
+++ b/deps/npm/docs/content/commands/npm-update.md
@@ -330,7 +330,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm.md b/deps/npm/docs/content/commands/npm.md
index 75157bd7b598..7789159b987f 100644
--- a/deps/npm/docs/content/commands/npm.md
+++ b/deps/npm/docs/content/commands/npm.md
@@ -14,7 +14,7 @@ Note: This command is unaware of workspaces.
### Version
-11.19.1
+11.20.0
### Description
diff --git a/deps/npm/docs/content/using-npm/config.md b/deps/npm/docs/content/using-npm/config.md
index 5d951493e8a1..71743e7fea3d 100644
--- a/deps/npm/docs/content/using-npm/config.md
+++ b/deps/npm/docs/content/using-npm/config.md
@@ -271,7 +271,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `allow-scripts-pending`
@@ -1473,11 +1473,14 @@ token access to all packages instead of limiting to specific packages.
#### `packages-and-scopes-permission`
* Default: null
-* Type: null, "read-only", "read-write", or "no-access"
+* Type: null, "read-only", "read-write", "read-write-stage-only", or
+ "no-access"
When creating a Granular Access Token with `npm token create`, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
@@ -1575,6 +1578,9 @@ Set to `false` to suppress the progress bar.
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the `provenance-file` config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
+
This config cannot be used with: `provenance-file`
#### `provenance-file`
@@ -1584,6 +1590,9 @@ This config cannot be used with: `provenance-file`
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
+
This config cannot be used with: `provenance`
#### `proxy`
diff --git a/deps/npm/docs/output/commands/npm-access.html b/deps/npm/docs/output/commands/npm-access.html
index ac6df64b960b..9e232c895e99 100644
--- a/deps/npm/docs/output/commands/npm-access.html
+++ b/deps/npm/docs/output/commands/npm-access.html
@@ -186,9 +186,9 @@
-
+
npm-access
- @11.19.1
+ @11.20.0
Set access level on published packages
diff --git a/deps/npm/docs/output/commands/npm-adduser.html b/deps/npm/docs/output/commands/npm-adduser.html
index 29aec6314e96..f1fdd66f3096 100644
--- a/deps/npm/docs/output/commands/npm-adduser.html
+++ b/deps/npm/docs/output/commands/npm-adduser.html
@@ -186,9 +186,9 @@
-
+
npm-adduser
- @11.19.1
+ @11.20.0
Add a registry user account
diff --git a/deps/npm/docs/output/commands/npm-approve-scripts.html b/deps/npm/docs/output/commands/npm-approve-scripts.html
index 3d61cc8ea23a..8b54f89168b2 100644
--- a/deps/npm/docs/output/commands/npm-approve-scripts.html
+++ b/deps/npm/docs/output/commands/npm-approve-scripts.html
@@ -186,9 +186,9 @@
-
+
npm-approve-scripts
- @11.19.1
+ @11.20.0
Approve install scripts for specific dependencies
diff --git a/deps/npm/docs/output/commands/npm-audit.html b/deps/npm/docs/output/commands/npm-audit.html
index 9117faa9bed5..d093dc1d253d 100644
--- a/deps/npm/docs/output/commands/npm-audit.html
+++ b/deps/npm/docs/output/commands/npm-audit.html
@@ -186,9 +186,9 @@
-
+
npm-audit
- @11.19.1
+ @11.20.0
Run a security audit
diff --git a/deps/npm/docs/output/commands/npm-bugs.html b/deps/npm/docs/output/commands/npm-bugs.html
index 63f4c29210a2..98cc06a6698f 100644
--- a/deps/npm/docs/output/commands/npm-bugs.html
+++ b/deps/npm/docs/output/commands/npm-bugs.html
@@ -186,9 +186,9 @@
-
+
npm-bugs
- @11.19.1
+ @11.20.0
Report bugs for a package in a web browser
diff --git a/deps/npm/docs/output/commands/npm-cache.html b/deps/npm/docs/output/commands/npm-cache.html
index 3377b00cc56c..9f49c5378467 100644
--- a/deps/npm/docs/output/commands/npm-cache.html
+++ b/deps/npm/docs/output/commands/npm-cache.html
@@ -186,9 +186,9 @@
-
+
npm-cache
- @11.19.1
+ @11.20.0
Manipulates packages cache
diff --git a/deps/npm/docs/output/commands/npm-ci.html b/deps/npm/docs/output/commands/npm-ci.html
index edde5bbdef66..5ef13e2947be 100644
--- a/deps/npm/docs/output/commands/npm-ci.html
+++ b/deps/npm/docs/output/commands/npm-ci.html
@@ -186,9 +186,9 @@
-
+
npm-ci
- @11.19.1
+ @11.20.0
Clean install a project
@@ -414,6 +414,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-completion.html b/deps/npm/docs/output/commands/npm-completion.html
index b5a6f445d451..69e1b5771a2d 100644
--- a/deps/npm/docs/output/commands/npm-completion.html
+++ b/deps/npm/docs/output/commands/npm-completion.html
@@ -186,9 +186,9 @@
-
+
npm-completion
- @11.19.1
+ @11.20.0
Tab Completion for npm
diff --git a/deps/npm/docs/output/commands/npm-config.html b/deps/npm/docs/output/commands/npm-config.html
index c9ea9080cf78..bb6a7770b935 100644
--- a/deps/npm/docs/output/commands/npm-config.html
+++ b/deps/npm/docs/output/commands/npm-config.html
@@ -186,9 +186,9 @@
-
+
npm-config
- @11.19.1
+ @11.20.0
Manage the npm configuration files
diff --git a/deps/npm/docs/output/commands/npm-dedupe.html b/deps/npm/docs/output/commands/npm-dedupe.html
index abe4a229e77c..8437b66e5339 100644
--- a/deps/npm/docs/output/commands/npm-dedupe.html
+++ b/deps/npm/docs/output/commands/npm-dedupe.html
@@ -186,9 +186,9 @@
-
+
npm-dedupe
- @11.19.1
+ @11.20.0
Reduce duplication in the package tree
diff --git a/deps/npm/docs/output/commands/npm-deny-scripts.html b/deps/npm/docs/output/commands/npm-deny-scripts.html
index 3a56f32dc977..537897998557 100644
--- a/deps/npm/docs/output/commands/npm-deny-scripts.html
+++ b/deps/npm/docs/output/commands/npm-deny-scripts.html
@@ -186,9 +186,9 @@
-
+
npm-deny-scripts
- @11.19.1
+ @11.20.0
Deny install scripts for specific dependencies
diff --git a/deps/npm/docs/output/commands/npm-deprecate.html b/deps/npm/docs/output/commands/npm-deprecate.html
index 90f45466cad9..bbd8d76fac03 100644
--- a/deps/npm/docs/output/commands/npm-deprecate.html
+++ b/deps/npm/docs/output/commands/npm-deprecate.html
@@ -186,9 +186,9 @@
-
+
npm-deprecate
- @11.19.1
+ @11.20.0
Deprecate a version of a package
diff --git a/deps/npm/docs/output/commands/npm-diff.html b/deps/npm/docs/output/commands/npm-diff.html
index fba245e3b33a..0a23ac8cf7b3 100644
--- a/deps/npm/docs/output/commands/npm-diff.html
+++ b/deps/npm/docs/output/commands/npm-diff.html
@@ -186,9 +186,9 @@
-
+
npm-diff
- @11.19.1
+ @11.20.0
The registry diff command
diff --git a/deps/npm/docs/output/commands/npm-dist-tag.html b/deps/npm/docs/output/commands/npm-dist-tag.html
index 2d42ee8e3e84..b5d56fa965f6 100644
--- a/deps/npm/docs/output/commands/npm-dist-tag.html
+++ b/deps/npm/docs/output/commands/npm-dist-tag.html
@@ -186,9 +186,9 @@
-
+
npm-dist-tag
- @11.19.1
+ @11.20.0
Modify package distribution tags
diff --git a/deps/npm/docs/output/commands/npm-docs.html b/deps/npm/docs/output/commands/npm-docs.html
index 98295c7943e0..ee20bd23abd1 100644
--- a/deps/npm/docs/output/commands/npm-docs.html
+++ b/deps/npm/docs/output/commands/npm-docs.html
@@ -186,9 +186,9 @@
-
+
npm-docs
- @11.19.1
+ @11.20.0
Open documentation for a package in a web browser
diff --git a/deps/npm/docs/output/commands/npm-doctor.html b/deps/npm/docs/output/commands/npm-doctor.html
index 096f12bf3b80..c7a3368b35cd 100644
--- a/deps/npm/docs/output/commands/npm-doctor.html
+++ b/deps/npm/docs/output/commands/npm-doctor.html
@@ -186,9 +186,9 @@
-
+
npm-doctor
- @11.19.1
+ @11.20.0
Check the health of your npm environment
diff --git a/deps/npm/docs/output/commands/npm-edit.html b/deps/npm/docs/output/commands/npm-edit.html
index 7a555a8f39a4..ab465f52017f 100644
--- a/deps/npm/docs/output/commands/npm-edit.html
+++ b/deps/npm/docs/output/commands/npm-edit.html
@@ -186,9 +186,9 @@
-
+
npm-edit
- @11.19.1
+ @11.20.0
Edit an installed package
diff --git a/deps/npm/docs/output/commands/npm-exec.html b/deps/npm/docs/output/commands/npm-exec.html
index 94e8e68c05f1..67b114949b73 100644
--- a/deps/npm/docs/output/commands/npm-exec.html
+++ b/deps/npm/docs/output/commands/npm-exec.html
@@ -186,9 +186,9 @@
-
+
npm-exec
- @11.19.1
+ @11.20.0
Run a command from a local or remote npm package
@@ -324,6 +324,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-explain.html b/deps/npm/docs/output/commands/npm-explain.html
index ccf68b227121..3cc89e27ceb0 100644
--- a/deps/npm/docs/output/commands/npm-explain.html
+++ b/deps/npm/docs/output/commands/npm-explain.html
@@ -186,9 +186,9 @@
-
+
npm-explain
- @11.19.1
+ @11.20.0
Explain installed packages
diff --git a/deps/npm/docs/output/commands/npm-explore.html b/deps/npm/docs/output/commands/npm-explore.html
index 7b4d6a2ed2c4..028b6ba5ba81 100644
--- a/deps/npm/docs/output/commands/npm-explore.html
+++ b/deps/npm/docs/output/commands/npm-explore.html
@@ -186,9 +186,9 @@
-
+
npm-explore
- @11.19.1
+ @11.20.0
Browse an installed package
diff --git a/deps/npm/docs/output/commands/npm-find-dupes.html b/deps/npm/docs/output/commands/npm-find-dupes.html
index 19b5ae4ffcfa..3476968389e8 100644
--- a/deps/npm/docs/output/commands/npm-find-dupes.html
+++ b/deps/npm/docs/output/commands/npm-find-dupes.html
@@ -186,9 +186,9 @@
-
+
npm-find-dupes
- @11.19.1
+ @11.20.0
Find duplication in the package tree
diff --git a/deps/npm/docs/output/commands/npm-fund.html b/deps/npm/docs/output/commands/npm-fund.html
index c657d182afd3..181e029e6c12 100644
--- a/deps/npm/docs/output/commands/npm-fund.html
+++ b/deps/npm/docs/output/commands/npm-fund.html
@@ -186,9 +186,9 @@
-
+
npm-fund
- @11.19.1
+ @11.20.0
Retrieve funding information
diff --git a/deps/npm/docs/output/commands/npm-get.html b/deps/npm/docs/output/commands/npm-get.html
index 59eaf5e577cb..02feaf3e7370 100644
--- a/deps/npm/docs/output/commands/npm-get.html
+++ b/deps/npm/docs/output/commands/npm-get.html
@@ -186,9 +186,9 @@
-
+
npm-get
- @11.19.1
+ @11.20.0
Get a value from the npm configuration
diff --git a/deps/npm/docs/output/commands/npm-help-search.html b/deps/npm/docs/output/commands/npm-help-search.html
index d4abfb29c360..b32d15859944 100644
--- a/deps/npm/docs/output/commands/npm-help-search.html
+++ b/deps/npm/docs/output/commands/npm-help-search.html
@@ -186,9 +186,9 @@
-
+
npm-help-search
- @11.19.1
+ @11.20.0
Search npm help documentation
diff --git a/deps/npm/docs/output/commands/npm-help.html b/deps/npm/docs/output/commands/npm-help.html
index d4fe535e8bd0..4e0a516a694a 100644
--- a/deps/npm/docs/output/commands/npm-help.html
+++ b/deps/npm/docs/output/commands/npm-help.html
@@ -186,9 +186,9 @@
-
+
npm-help
- @11.19.1
+ @11.20.0
Get help on npm
diff --git a/deps/npm/docs/output/commands/npm-init.html b/deps/npm/docs/output/commands/npm-init.html
index af686f90a7ac..b0fefd704084 100644
--- a/deps/npm/docs/output/commands/npm-init.html
+++ b/deps/npm/docs/output/commands/npm-init.html
@@ -186,9 +186,9 @@
-
+
npm-init
- @11.19.1
+ @11.20.0
Create a package.json file
diff --git a/deps/npm/docs/output/commands/npm-install-ci-test.html b/deps/npm/docs/output/commands/npm-install-ci-test.html
index bdf779e2eef8..1c62ffb640b1 100644
--- a/deps/npm/docs/output/commands/npm-install-ci-test.html
+++ b/deps/npm/docs/output/commands/npm-install-ci-test.html
@@ -186,9 +186,9 @@
-
+
npm-install-ci-test
- @11.19.1
+ @11.20.0
Install a project with a clean slate and run tests
@@ -378,6 +378,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-install-scripts.html b/deps/npm/docs/output/commands/npm-install-scripts.html
index 8174e90a5094..746b9bcbb9c9 100644
--- a/deps/npm/docs/output/commands/npm-install-scripts.html
+++ b/deps/npm/docs/output/commands/npm-install-scripts.html
@@ -186,9 +186,9 @@
-
+
npm-install-scripts
- @11.19.1
+ @11.20.0
Manage install-script approvals for dependencies
diff --git a/deps/npm/docs/output/commands/npm-install-test.html b/deps/npm/docs/output/commands/npm-install-test.html
index e75fb52d3239..17542aae9e77 100644
--- a/deps/npm/docs/output/commands/npm-install-test.html
+++ b/deps/npm/docs/output/commands/npm-install-test.html
@@ -186,9 +186,9 @@
-
+
npm-install-test
- @11.19.1
+ @11.20.0
Install package(s) and run tests
@@ -434,6 +434,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-install.html b/deps/npm/docs/output/commands/npm-install.html
index ed78f6576bb7..47ac2f056289 100644
--- a/deps/npm/docs/output/commands/npm-install.html
+++ b/deps/npm/docs/output/commands/npm-install.html
@@ -186,9 +186,9 @@
-
+
npm-install
- @11.19.1
+ @11.20.0
Install a package
@@ -709,6 +709,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-link.html b/deps/npm/docs/output/commands/npm-link.html
index aa01ff7a259a..bb707c9d73be 100644
--- a/deps/npm/docs/output/commands/npm-link.html
+++ b/deps/npm/docs/output/commands/npm-link.html
@@ -186,9 +186,9 @@
-
+
npm-link
- @11.19.1
+ @11.20.0
Symlink a package folder
diff --git a/deps/npm/docs/output/commands/npm-ll.html b/deps/npm/docs/output/commands/npm-ll.html
index f8df2515bfa4..c54f5a6e41ef 100644
--- a/deps/npm/docs/output/commands/npm-ll.html
+++ b/deps/npm/docs/output/commands/npm-ll.html
@@ -186,9 +186,9 @@
-
+
npm-ll
- @11.19.1
+ @11.20.0
List installed packages
diff --git a/deps/npm/docs/output/commands/npm-login.html b/deps/npm/docs/output/commands/npm-login.html
index 1c6d938ec6c1..16703d1ce173 100644
--- a/deps/npm/docs/output/commands/npm-login.html
+++ b/deps/npm/docs/output/commands/npm-login.html
@@ -186,9 +186,9 @@
-
+
npm-login
- @11.19.1
+ @11.20.0
Login to a registry user account
diff --git a/deps/npm/docs/output/commands/npm-logout.html b/deps/npm/docs/output/commands/npm-logout.html
index cf319a086f89..f5712b456340 100644
--- a/deps/npm/docs/output/commands/npm-logout.html
+++ b/deps/npm/docs/output/commands/npm-logout.html
@@ -186,9 +186,9 @@
-
+
npm-logout
- @11.19.1
+ @11.20.0
Log out of the registry
diff --git a/deps/npm/docs/output/commands/npm-ls.html b/deps/npm/docs/output/commands/npm-ls.html
index b733762be373..e09112e22d87 100644
--- a/deps/npm/docs/output/commands/npm-ls.html
+++ b/deps/npm/docs/output/commands/npm-ls.html
@@ -186,9 +186,9 @@
-
+
npm-ls
- @11.19.1
+ @11.20.0
List installed packages
@@ -209,7 +209,7 @@ Description
Positional arguments are name@version-range identifiers, which will limit the results to only the paths to the packages named.
Note that nested packages will also show the paths to the specified packages.
For example, running npm ls promzard in npm's source tree will show:
-npm@11.19.1 /path/to/npm
+npm@11.20.0 /path/to/npm
└─┬ init-package-json@0.0.4
└── promzard@0.1.5
diff --git a/deps/npm/docs/output/commands/npm-org.html b/deps/npm/docs/output/commands/npm-org.html
index 6a2c22951a60..7618c07e5557 100644
--- a/deps/npm/docs/output/commands/npm-org.html
+++ b/deps/npm/docs/output/commands/npm-org.html
@@ -186,9 +186,9 @@
-
+
npm-org
- @11.19.1
+ @11.20.0
Manage orgs
diff --git a/deps/npm/docs/output/commands/npm-outdated.html b/deps/npm/docs/output/commands/npm-outdated.html
index b85880371cdf..b4a7eaf72238 100644
--- a/deps/npm/docs/output/commands/npm-outdated.html
+++ b/deps/npm/docs/output/commands/npm-outdated.html
@@ -186,9 +186,9 @@
-
+
npm-outdated
- @11.19.1
+ @11.20.0
Check for outdated packages
diff --git a/deps/npm/docs/output/commands/npm-owner.html b/deps/npm/docs/output/commands/npm-owner.html
index 6b8afff7ba36..83a0cabfe398 100644
--- a/deps/npm/docs/output/commands/npm-owner.html
+++ b/deps/npm/docs/output/commands/npm-owner.html
@@ -186,9 +186,9 @@
-
+
npm-owner
- @11.19.1
+ @11.20.0
Manage package owners
diff --git a/deps/npm/docs/output/commands/npm-pack.html b/deps/npm/docs/output/commands/npm-pack.html
index d7f148d92ed7..9acd4c9d20e9 100644
--- a/deps/npm/docs/output/commands/npm-pack.html
+++ b/deps/npm/docs/output/commands/npm-pack.html
@@ -186,9 +186,9 @@
-
+
npm-pack
- @11.19.1
+ @11.20.0
Create a tarball from a package
diff --git a/deps/npm/docs/output/commands/npm-ping.html b/deps/npm/docs/output/commands/npm-ping.html
index 3c49a0713166..72779cc45121 100644
--- a/deps/npm/docs/output/commands/npm-ping.html
+++ b/deps/npm/docs/output/commands/npm-ping.html
@@ -186,9 +186,9 @@
-
+
npm-ping
- @11.19.1
+ @11.20.0
Ping npm registry
diff --git a/deps/npm/docs/output/commands/npm-pkg.html b/deps/npm/docs/output/commands/npm-pkg.html
index d80ac21f9af3..7ae9d0b42fba 100644
--- a/deps/npm/docs/output/commands/npm-pkg.html
+++ b/deps/npm/docs/output/commands/npm-pkg.html
@@ -186,9 +186,9 @@
-
+
npm-pkg
- @11.19.1
+ @11.20.0
Manages your package.json
diff --git a/deps/npm/docs/output/commands/npm-prefix.html b/deps/npm/docs/output/commands/npm-prefix.html
index 1592a1d3048d..b0043c87e35f 100644
--- a/deps/npm/docs/output/commands/npm-prefix.html
+++ b/deps/npm/docs/output/commands/npm-prefix.html
@@ -186,9 +186,9 @@
-
+
npm-prefix
- @11.19.1
+ @11.20.0
Display prefix
diff --git a/deps/npm/docs/output/commands/npm-profile.html b/deps/npm/docs/output/commands/npm-profile.html
index 24f5db6d7f37..1183e9ef1f20 100644
--- a/deps/npm/docs/output/commands/npm-profile.html
+++ b/deps/npm/docs/output/commands/npm-profile.html
@@ -186,9 +186,9 @@
-
+
npm-profile
- @11.19.1
+ @11.20.0
Change settings on your registry profile
diff --git a/deps/npm/docs/output/commands/npm-prune.html b/deps/npm/docs/output/commands/npm-prune.html
index 736620c0a24a..97728f904ef0 100644
--- a/deps/npm/docs/output/commands/npm-prune.html
+++ b/deps/npm/docs/output/commands/npm-prune.html
@@ -186,9 +186,9 @@
-
+
npm-prune
- @11.19.1
+ @11.20.0
Remove extraneous packages
diff --git a/deps/npm/docs/output/commands/npm-publish.html b/deps/npm/docs/output/commands/npm-publish.html
index a20d56b8d10e..60a816323cde 100644
--- a/deps/npm/docs/output/commands/npm-publish.html
+++ b/deps/npm/docs/output/commands/npm-publish.html
@@ -186,9 +186,9 @@
-
+
npm-publish
- @11.19.1
+ @11.20.0
Publish a package
@@ -360,6 +360,8 @@ provenance
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the provenance-file config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
This config cannot be used with: provenance-file
provenance-file
@@ -367,6 +369,8 @@ provenance-file
- Type: Path
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
This config cannot be used with: provenance
See Also
diff --git a/deps/npm/docs/output/commands/npm-query.html b/deps/npm/docs/output/commands/npm-query.html
index a74342cf2782..0211cd7a25e2 100644
--- a/deps/npm/docs/output/commands/npm-query.html
+++ b/deps/npm/docs/output/commands/npm-query.html
@@ -186,9 +186,9 @@
-
+
npm-query
- @11.19.1
+ @11.20.0
Dependency selector query
diff --git a/deps/npm/docs/output/commands/npm-rebuild.html b/deps/npm/docs/output/commands/npm-rebuild.html
index 39403a70941d..f25623251ff1 100644
--- a/deps/npm/docs/output/commands/npm-rebuild.html
+++ b/deps/npm/docs/output/commands/npm-rebuild.html
@@ -186,9 +186,9 @@
-
+
npm-rebuild
- @11.19.1
+ @11.20.0
Rebuild a package
@@ -286,6 +286,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-repo.html b/deps/npm/docs/output/commands/npm-repo.html
index 5337679c8248..943c5177cbf3 100644
--- a/deps/npm/docs/output/commands/npm-repo.html
+++ b/deps/npm/docs/output/commands/npm-repo.html
@@ -186,9 +186,9 @@
-
+
npm-repo
- @11.19.1
+ @11.20.0
Open package repository page in the browser
diff --git a/deps/npm/docs/output/commands/npm-restart.html b/deps/npm/docs/output/commands/npm-restart.html
index 0786bdc34a54..fce2e5b294ed 100644
--- a/deps/npm/docs/output/commands/npm-restart.html
+++ b/deps/npm/docs/output/commands/npm-restart.html
@@ -186,9 +186,9 @@
-
+
npm-restart
- @11.19.1
+ @11.20.0
Restart a package
diff --git a/deps/npm/docs/output/commands/npm-root.html b/deps/npm/docs/output/commands/npm-root.html
index 165223c6fdb6..88acaa9e893f 100644
--- a/deps/npm/docs/output/commands/npm-root.html
+++ b/deps/npm/docs/output/commands/npm-root.html
@@ -186,9 +186,9 @@
-
+
npm-root
- @11.19.1
+ @11.20.0
Display npm root
diff --git a/deps/npm/docs/output/commands/npm-run.html b/deps/npm/docs/output/commands/npm-run.html
index 15ca998eb8a8..ae867e8897f4 100644
--- a/deps/npm/docs/output/commands/npm-run.html
+++ b/deps/npm/docs/output/commands/npm-run.html
@@ -186,9 +186,9 @@
-
+
npm-run
- @11.19.1
+ @11.20.0
Run arbitrary package scripts
diff --git a/deps/npm/docs/output/commands/npm-sbom.html b/deps/npm/docs/output/commands/npm-sbom.html
index fe84c36327a6..ec88592fa2df 100644
--- a/deps/npm/docs/output/commands/npm-sbom.html
+++ b/deps/npm/docs/output/commands/npm-sbom.html
@@ -186,9 +186,9 @@
-
+
npm-sbom
- @11.19.1
+ @11.20.0
Generate a Software Bill of Materials (SBOM)
diff --git a/deps/npm/docs/output/commands/npm-search.html b/deps/npm/docs/output/commands/npm-search.html
index 98006e7d2253..57b07bf1be84 100644
--- a/deps/npm/docs/output/commands/npm-search.html
+++ b/deps/npm/docs/output/commands/npm-search.html
@@ -186,9 +186,9 @@
-
+
npm-search
- @11.19.1
+ @11.20.0
Search for packages
diff --git a/deps/npm/docs/output/commands/npm-set.html b/deps/npm/docs/output/commands/npm-set.html
index 6202cdf7b3cd..8ae84be02493 100644
--- a/deps/npm/docs/output/commands/npm-set.html
+++ b/deps/npm/docs/output/commands/npm-set.html
@@ -186,9 +186,9 @@
-
+
npm-set
- @11.19.1
+ @11.20.0
Set a value in the npm configuration
diff --git a/deps/npm/docs/output/commands/npm-shrinkwrap.html b/deps/npm/docs/output/commands/npm-shrinkwrap.html
index abb9c216e6da..761e5b79b266 100644
--- a/deps/npm/docs/output/commands/npm-shrinkwrap.html
+++ b/deps/npm/docs/output/commands/npm-shrinkwrap.html
@@ -186,9 +186,9 @@
-
+
npm-shrinkwrap
- @11.19.1
+ @11.20.0
Lock down dependency versions for publication
diff --git a/deps/npm/docs/output/commands/npm-stage.html b/deps/npm/docs/output/commands/npm-stage.html
index 74c4f7acddf0..4ffbe2c9cc0d 100644
--- a/deps/npm/docs/output/commands/npm-stage.html
+++ b/deps/npm/docs/output/commands/npm-stage.html
@@ -186,9 +186,9 @@
-
+
npm-stage
- @11.19.1
+ @11.20.0
Stage packages for publishing
@@ -433,7 +433,7 @@ Flags
--provenance |
false |
Boolean |
-When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. |
+When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. When the provenance-file config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped. |
diff --git a/deps/npm/docs/output/commands/npm-star.html b/deps/npm/docs/output/commands/npm-star.html
index 4ba2f61b1797..e627cb613ee6 100644
--- a/deps/npm/docs/output/commands/npm-star.html
+++ b/deps/npm/docs/output/commands/npm-star.html
@@ -186,9 +186,9 @@
-
+
npm-star
- @11.19.1
+ @11.20.0
Mark your favorite packages
diff --git a/deps/npm/docs/output/commands/npm-stars.html b/deps/npm/docs/output/commands/npm-stars.html
index a1c7c0a4fd9d..d87d857cbebd 100644
--- a/deps/npm/docs/output/commands/npm-stars.html
+++ b/deps/npm/docs/output/commands/npm-stars.html
@@ -186,9 +186,9 @@
-
+
npm-stars
- @11.19.1
+ @11.20.0
View packages marked as favorites
diff --git a/deps/npm/docs/output/commands/npm-start.html b/deps/npm/docs/output/commands/npm-start.html
index 063ac6b3d809..d276c536d4e0 100644
--- a/deps/npm/docs/output/commands/npm-start.html
+++ b/deps/npm/docs/output/commands/npm-start.html
@@ -186,9 +186,9 @@
-
+
npm-start
- @11.19.1
+ @11.20.0
Start a package
diff --git a/deps/npm/docs/output/commands/npm-stop.html b/deps/npm/docs/output/commands/npm-stop.html
index b4e84d2488de..bb7a86fe6e0c 100644
--- a/deps/npm/docs/output/commands/npm-stop.html
+++ b/deps/npm/docs/output/commands/npm-stop.html
@@ -186,9 +186,9 @@
-
+
npm-stop
- @11.19.1
+ @11.20.0
Stop a package
diff --git a/deps/npm/docs/output/commands/npm-team.html b/deps/npm/docs/output/commands/npm-team.html
index c9a7504b91fa..1d4fe77056d9 100644
--- a/deps/npm/docs/output/commands/npm-team.html
+++ b/deps/npm/docs/output/commands/npm-team.html
@@ -186,9 +186,9 @@
-
+
npm-team
- @11.19.1
+ @11.20.0
Manage organization teams and team memberships
diff --git a/deps/npm/docs/output/commands/npm-test.html b/deps/npm/docs/output/commands/npm-test.html
index bbb30678ba8c..22662fa99ad3 100644
--- a/deps/npm/docs/output/commands/npm-test.html
+++ b/deps/npm/docs/output/commands/npm-test.html
@@ -186,9 +186,9 @@
-
+
npm-test
- @11.19.1
+ @11.20.0
Test a package
diff --git a/deps/npm/docs/output/commands/npm-token.html b/deps/npm/docs/output/commands/npm-token.html
index 680c2aa534f8..7329915528df 100644
--- a/deps/npm/docs/output/commands/npm-token.html
+++ b/deps/npm/docs/output/commands/npm-token.html
@@ -186,9 +186,9 @@
-
+
npm-token
- @11.19.1
+ @11.20.0
Manage your authentication tokens
@@ -268,11 +268,14 @@ orgs
packages-and-scopes-permission
- Default: null
-- Type: null, "read-only", "read-write", or "no-access"
+- Type: null, "read-only", "read-write", "read-write-stage-only", or
+"no-access"
When creating a Granular Access Token with npm token create, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
orgs-permission
- Default: null
diff --git a/deps/npm/docs/output/commands/npm-trust.html b/deps/npm/docs/output/commands/npm-trust.html
index 6d531484035c..4f2cd57ecd5c 100644
--- a/deps/npm/docs/output/commands/npm-trust.html
+++ b/deps/npm/docs/output/commands/npm-trust.html
@@ -186,9 +186,9 @@
-
+
npm-trust
- @11.19.1
+ @11.20.0
Manage trusted publishing relationships between packages and CI/CD providers
diff --git a/deps/npm/docs/output/commands/npm-undeprecate.html b/deps/npm/docs/output/commands/npm-undeprecate.html
index d5239ca0cac0..6bf5195e4f09 100644
--- a/deps/npm/docs/output/commands/npm-undeprecate.html
+++ b/deps/npm/docs/output/commands/npm-undeprecate.html
@@ -186,9 +186,9 @@
-
+
npm-undeprecate
- @11.19.1
+ @11.20.0
Undeprecate a version of a package
diff --git a/deps/npm/docs/output/commands/npm-uninstall.html b/deps/npm/docs/output/commands/npm-uninstall.html
index 26991d034bd4..c7bd23fe17fd 100644
--- a/deps/npm/docs/output/commands/npm-uninstall.html
+++ b/deps/npm/docs/output/commands/npm-uninstall.html
@@ -186,9 +186,9 @@
-
+
npm-uninstall
- @11.19.1
+ @11.20.0
Remove a package
diff --git a/deps/npm/docs/output/commands/npm-unpublish.html b/deps/npm/docs/output/commands/npm-unpublish.html
index 4fda332a9615..80fbe894b176 100644
--- a/deps/npm/docs/output/commands/npm-unpublish.html
+++ b/deps/npm/docs/output/commands/npm-unpublish.html
@@ -186,9 +186,9 @@
-
+
npm-unpublish
- @11.19.1
+ @11.20.0
Remove a package from the registry
diff --git a/deps/npm/docs/output/commands/npm-unstar.html b/deps/npm/docs/output/commands/npm-unstar.html
index 25db54715ddb..f061163d223a 100644
--- a/deps/npm/docs/output/commands/npm-unstar.html
+++ b/deps/npm/docs/output/commands/npm-unstar.html
@@ -186,9 +186,9 @@
-
+
npm-unstar
- @11.19.1
+ @11.20.0
Remove an item from your favorite packages
diff --git a/deps/npm/docs/output/commands/npm-update.html b/deps/npm/docs/output/commands/npm-update.html
index fff2f70073cd..6d8f260b7be9 100644
--- a/deps/npm/docs/output/commands/npm-update.html
+++ b/deps/npm/docs/output/commands/npm-update.html
@@ -186,9 +186,9 @@
-
+
npm-update
- @11.19.1
+ @11.20.0
Update packages
@@ -430,6 +430,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-version.html b/deps/npm/docs/output/commands/npm-version.html
index 310abe5db903..22667d199ee0 100644
--- a/deps/npm/docs/output/commands/npm-version.html
+++ b/deps/npm/docs/output/commands/npm-version.html
@@ -186,9 +186,9 @@
-
+
npm-version
- @11.19.1
+ @11.20.0
Bump a package version
diff --git a/deps/npm/docs/output/commands/npm-view.html b/deps/npm/docs/output/commands/npm-view.html
index 18f28fe17077..d6892fd94d54 100644
--- a/deps/npm/docs/output/commands/npm-view.html
+++ b/deps/npm/docs/output/commands/npm-view.html
@@ -186,9 +186,9 @@
-
+
npm-view
- @11.19.1
+ @11.20.0
View registry info
diff --git a/deps/npm/docs/output/commands/npm-whoami.html b/deps/npm/docs/output/commands/npm-whoami.html
index 91a7d6e2288d..de1960ac1728 100644
--- a/deps/npm/docs/output/commands/npm-whoami.html
+++ b/deps/npm/docs/output/commands/npm-whoami.html
@@ -186,9 +186,9 @@
-
+
npm-whoami
- @11.19.1
+ @11.20.0
Display npm username
diff --git a/deps/npm/docs/output/commands/npm.html b/deps/npm/docs/output/commands/npm.html
index 99674e1362df..0f03bc8548e8 100644
--- a/deps/npm/docs/output/commands/npm.html
+++ b/deps/npm/docs/output/commands/npm.html
@@ -186,9 +186,9 @@
-
+
npm
- @11.19.1
+ @11.20.0
javascript package manager
@@ -203,7 +203,7 @@ Table of contents
Note: This command is unaware of workspaces.
Version
-11.19.1
+11.20.0
Description
npm is the package manager for the Node JavaScript platform.
It puts modules in place so that node can find them, and manages dependency conflicts intelligently.
diff --git a/deps/npm/docs/output/commands/npx.html b/deps/npm/docs/output/commands/npx.html
index d3cb1e00cc5b..80673580a6fb 100644
--- a/deps/npm/docs/output/commands/npx.html
+++ b/deps/npm/docs/output/commands/npx.html
@@ -186,9 +186,9 @@
-
+
npx
- @11.19.1
+ @11.20.0
Run a command from a local or remote npm package
diff --git a/deps/npm/docs/output/configuring-npm/folders.html b/deps/npm/docs/output/configuring-npm/folders.html
index 3e86bf9a9ee5..edf68a7fda4f 100644
--- a/deps/npm/docs/output/configuring-npm/folders.html
+++ b/deps/npm/docs/output/configuring-npm/folders.html
@@ -186,9 +186,9 @@
-
+
Folders
- @11.19.1
+ @11.20.0
Folder structures used by npm
diff --git a/deps/npm/docs/output/configuring-npm/install.html b/deps/npm/docs/output/configuring-npm/install.html
index 610fc057a134..8356ea4bc554 100644
--- a/deps/npm/docs/output/configuring-npm/install.html
+++ b/deps/npm/docs/output/configuring-npm/install.html
@@ -186,9 +186,9 @@
-
+
Install
- @11.19.1
+ @11.20.0
Download and install node and npm
diff --git a/deps/npm/docs/output/configuring-npm/npm-global.html b/deps/npm/docs/output/configuring-npm/npm-global.html
index 3e86bf9a9ee5..edf68a7fda4f 100644
--- a/deps/npm/docs/output/configuring-npm/npm-global.html
+++ b/deps/npm/docs/output/configuring-npm/npm-global.html
@@ -186,9 +186,9 @@
-
+
Folders
- @11.19.1
+ @11.20.0
Folder structures used by npm
diff --git a/deps/npm/docs/output/configuring-npm/npm-json.html b/deps/npm/docs/output/configuring-npm/npm-json.html
index 97a03a6d6175..70ef8ced0fcf 100644
--- a/deps/npm/docs/output/configuring-npm/npm-json.html
+++ b/deps/npm/docs/output/configuring-npm/npm-json.html
@@ -186,9 +186,9 @@
-
+
package.json
- @11.19.1
+ @11.20.0
Specifics of npm's package.json handling
diff --git a/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html b/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html
index 134524b16af6..eb90cfd59de3 100644
--- a/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html
+++ b/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html
@@ -186,9 +186,9 @@
-
+
npm-shrinkwrap.json
- @11.19.1
+ @11.20.0
A publishable lockfile
diff --git a/deps/npm/docs/output/configuring-npm/npmrc.html b/deps/npm/docs/output/configuring-npm/npmrc.html
index a5eb291b57ca..462664c73259 100644
--- a/deps/npm/docs/output/configuring-npm/npmrc.html
+++ b/deps/npm/docs/output/configuring-npm/npmrc.html
@@ -186,9 +186,9 @@
-
+
.npmrc
- @11.19.1
+ @11.20.0
The npm config files
diff --git a/deps/npm/docs/output/configuring-npm/package-json.html b/deps/npm/docs/output/configuring-npm/package-json.html
index 97a03a6d6175..70ef8ced0fcf 100644
--- a/deps/npm/docs/output/configuring-npm/package-json.html
+++ b/deps/npm/docs/output/configuring-npm/package-json.html
@@ -186,9 +186,9 @@
-
+
package.json
- @11.19.1
+ @11.20.0
Specifics of npm's package.json handling
diff --git a/deps/npm/docs/output/configuring-npm/package-lock-json.html b/deps/npm/docs/output/configuring-npm/package-lock-json.html
index 9a4f1631b337..8022b532fa43 100644
--- a/deps/npm/docs/output/configuring-npm/package-lock-json.html
+++ b/deps/npm/docs/output/configuring-npm/package-lock-json.html
@@ -186,9 +186,9 @@
-
+
package-lock.json
- @11.19.1
+ @11.20.0
A manifestation of the manifest
diff --git a/deps/npm/docs/output/using-npm/config.html b/deps/npm/docs/output/using-npm/config.html
index ac5829fba75d..457b0d079bd1 100644
--- a/deps/npm/docs/output/using-npm/config.html
+++ b/deps/npm/docs/output/using-npm/config.html
@@ -186,9 +186,9 @@
-
+
Config
- @11.19.1
+ @11.20.0
About npm configuration
@@ -406,6 +406,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
allow-scripts-pending
- Default: false
@@ -1266,11 +1267,14 @@ packages-all
packages-and-scopes-permission
- Default: null
-- Type: null, "read-only", "read-write", or "no-access"
+- Type: null, "read-only", "read-write", "read-write-stage-only", or
+"no-access"
When creating a Granular Access Token with npm token create, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
parseable
- Default: false
@@ -1339,6 +1343,8 @@ provenance
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the provenance-file config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
This config cannot be used with: provenance-file
provenance-file
@@ -1346,6 +1352,8 @@ provenance-file
- Type: Path
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
This config cannot be used with: provenance
proxy
diff --git a/deps/npm/docs/output/using-npm/dependency-selectors.html b/deps/npm/docs/output/using-npm/dependency-selectors.html
index c56b5e6c4027..baa45c36cbbf 100644
--- a/deps/npm/docs/output/using-npm/dependency-selectors.html
+++ b/deps/npm/docs/output/using-npm/dependency-selectors.html
@@ -186,9 +186,9 @@
-
+
Dependency Selectors
- @11.19.1
+ @11.20.0
Dependency Selector Syntax & Querying
diff --git a/deps/npm/docs/output/using-npm/developers.html b/deps/npm/docs/output/using-npm/developers.html
index 984f28bfe7b2..27c9b109d8ec 100644
--- a/deps/npm/docs/output/using-npm/developers.html
+++ b/deps/npm/docs/output/using-npm/developers.html
@@ -186,9 +186,9 @@
-
+
Developers
- @11.19.1
+ @11.20.0
Developer guide
diff --git a/deps/npm/docs/output/using-npm/logging.html b/deps/npm/docs/output/using-npm/logging.html
index f6f6dd742f12..08314392eea5 100644
--- a/deps/npm/docs/output/using-npm/logging.html
+++ b/deps/npm/docs/output/using-npm/logging.html
@@ -186,9 +186,9 @@
-
+
Logging
- @11.19.1
+ @11.20.0
Why, What & How we Log
diff --git a/deps/npm/docs/output/using-npm/orgs.html b/deps/npm/docs/output/using-npm/orgs.html
index f579fcbbac1f..242620475df7 100644
--- a/deps/npm/docs/output/using-npm/orgs.html
+++ b/deps/npm/docs/output/using-npm/orgs.html
@@ -186,9 +186,9 @@
-
+
Organizations
- @11.19.1
+ @11.20.0
Working with teams & organizations
diff --git a/deps/npm/docs/output/using-npm/package-spec.html b/deps/npm/docs/output/using-npm/package-spec.html
index 620f470d109b..b7adbecf2d54 100644
--- a/deps/npm/docs/output/using-npm/package-spec.html
+++ b/deps/npm/docs/output/using-npm/package-spec.html
@@ -186,9 +186,9 @@
-
+
Package spec
- @11.19.1
+ @11.20.0
Package name specifier
diff --git a/deps/npm/docs/output/using-npm/registry.html b/deps/npm/docs/output/using-npm/registry.html
index e61715c22e4b..4da60fd44fad 100644
--- a/deps/npm/docs/output/using-npm/registry.html
+++ b/deps/npm/docs/output/using-npm/registry.html
@@ -186,9 +186,9 @@
-
+
Registry
- @11.19.1
+ @11.20.0
The JavaScript Package Registry
diff --git a/deps/npm/docs/output/using-npm/removal.html b/deps/npm/docs/output/using-npm/removal.html
index 07ee6c06bc40..26f86fd39215 100644
--- a/deps/npm/docs/output/using-npm/removal.html
+++ b/deps/npm/docs/output/using-npm/removal.html
@@ -186,9 +186,9 @@
-
+
Removal
- @11.19.1
+ @11.20.0
Cleaning the slate
diff --git a/deps/npm/docs/output/using-npm/scope.html b/deps/npm/docs/output/using-npm/scope.html
index a08571ebfda3..fa268bacf0e5 100644
--- a/deps/npm/docs/output/using-npm/scope.html
+++ b/deps/npm/docs/output/using-npm/scope.html
@@ -186,9 +186,9 @@
-
+
Scope
- @11.19.1
+ @11.20.0
Scoped packages
diff --git a/deps/npm/docs/output/using-npm/scripts.html b/deps/npm/docs/output/using-npm/scripts.html
index 4e852304a114..bc7875c23682 100644
--- a/deps/npm/docs/output/using-npm/scripts.html
+++ b/deps/npm/docs/output/using-npm/scripts.html
@@ -186,9 +186,9 @@
-
+
Scripts
- @11.19.1
+ @11.20.0
How npm handles the "scripts" field
diff --git a/deps/npm/docs/output/using-npm/workspaces.html b/deps/npm/docs/output/using-npm/workspaces.html
index ec3d3abed055..412a16b9f039 100644
--- a/deps/npm/docs/output/using-npm/workspaces.html
+++ b/deps/npm/docs/output/using-npm/workspaces.html
@@ -186,9 +186,9 @@
-
+
Workspaces
- @11.19.1
+ @11.20.0
Working with workspaces
diff --git a/deps/npm/lib/commands/token.js b/deps/npm/lib/commands/token.js
index 8f54e9d8725d..f3fce31af8d5 100644
--- a/deps/npm/lib/commands/token.js
+++ b/deps/npm/lib/commands/token.js
@@ -171,6 +171,25 @@ class Token extends BaseCommand {
const validCIDR = await this.validateCIDRList(cidr)
+ // Warn when creating a token that can publish directly to the registry.
+ // Only 'read-write' package/scope permission grants direct-publish; stage-only
+ // tokens ('read-write-stage-only') stage releases instead, and non-publishing
+ // permissions (read-only/no-access) can't publish at all, so both stay silent.
+ // bypass-2fa is orthogonal — it removes the 2FA requirement but grants no
+ // publish capability on its own — so it is not part of this trigger.
+ if (packagesAndScopesPermission === 'read-write') {
+ // Deprecation notice for direct-publish tokens; see github/npm#15609.
+ log.warn(
+ 'token',
+ 'Creating a token that can publish directly to the registry. ' +
+ 'Consider `--packages-and-scopes-permission=read-write-stage-only` ' +
+ 'instead — with a stage-only token, your releases go to a staging ' +
+ 'queue for you to approve before they go public. Bypass-2FA tokens ' +
+ 'with direct-publish access will stop working in January 2027. ' +
+ 'See https://gh.io/bypass-2fa-tokens-no-longer-publish.'
+ )
+ }
+
/* istanbul ignore if - skip testing read input */
if (!password) {
password = await readUserInfo.password()
diff --git a/deps/npm/lib/utils/allow-scripts-writer.js b/deps/npm/lib/utils/allow-scripts-writer.js
index 6964279f2f2e..26d13b164e34 100644
--- a/deps/npm/lib/utils/allow-scripts-writer.js
+++ b/deps/npm/lib/utils/allow-scripts-writer.js
@@ -2,6 +2,7 @@ const npa = require('npm-package-arg')
const { log } = require('proc-log')
const {
getTrustedRegistryIdentity,
+ matchFileOrDir,
resolvedSourceSpecs,
} = require('@npmcli/arborist/lib/script-allowed.js')
@@ -150,7 +151,7 @@ const isNameOnlyKey = (key) => {
const keyTargetsNode = (key, node) => {
let parsed
try {
- parsed = npa(key)
+ parsed = npa(key, node?.root?.path)
} catch {
return false
}
@@ -179,6 +180,7 @@ const keyTargetsNode = (key, node) => {
}
case 'file':
case 'directory':
+ return matchFileOrDir(node, parsed)
case 'remote':
return resolvedSourceSpecs(node)
.some(resolved => resolved === parsed.saveSpec || resolved === parsed.fetchSpec)
diff --git a/deps/npm/lib/utils/key-values.js b/deps/npm/lib/utils/key-values.js
index cf54304da6b4..ec9f40989311 100644
--- a/deps/npm/lib/utils/key-values.js
+++ b/deps/npm/lib/utils/key-values.js
@@ -26,11 +26,23 @@ function logObject (values, { chalk, json, predicate = defaultPredicate }) {
}
function logStageItem (item, { chalk }) {
- const { id, packageName, version, tag, createdAt, actor, actorType, shasum, ...rest } = item
+ const {
+ id,
+ packageName,
+ version,
+ tag,
+ createdAt,
+ actor,
+ actorType,
+ shasum,
+ status,
+ ...rest
+ } = item
logObject({
id,
'package name': packageName,
version,
+ status,
tag,
'date staged': createdAt,
'staged by': actorType ? `${actor} (${actorType})` : actor,
diff --git a/deps/npm/lib/utils/oidc.js b/deps/npm/lib/utils/oidc.js
index 00f32c642621..203aaf3143a7 100644
--- a/deps/npm/lib/utils/oidc.js
+++ b/deps/npm/lib/utils/oidc.js
@@ -143,8 +143,9 @@ async function oidc ({ packageName, registry, opts, config }) {
try {
const isDefaultProvenance = config.isDefault('provenance')
- // CircleCI doesn't support provenance yet, so skip the auto-enable logic
- if (isDefaultProvenance && !ciInfo.CIRCLE) {
+ // CircleCI doesn't support provenance yet, so skip the auto-enable logic.
+ // An explicitly provided provenance file always takes precedence over auto-generated provenance
+ if (isDefaultProvenance && !ciInfo.CIRCLE && !opts.provenanceFile) {
const [headerB64, payloadB64] = idToken.split('.')
if (headerB64 && payloadB64) {
const payloadJson = Buffer.from(payloadB64, 'base64').toString('utf8')
@@ -158,7 +159,6 @@ async function oidc ({ packageName, registry, opts, config }) {
if (visibility?.public) {
log.verbose('oidc', `Enabling provenance`)
opts.provenance = true
- config.set('provenance', true, 'user')
}
}
}
diff --git a/deps/npm/lib/utils/reify-output.js b/deps/npm/lib/utils/reify-output.js
index fa229a318d26..aa32e116f423 100644
--- a/deps/npm/lib/utils/reify-output.js
+++ b/deps/npm/lib/utils/reify-output.js
@@ -44,7 +44,8 @@ const reifyOutput = (npm, arb, extras = {}) => {
}
if (diff) {
- const showDiff = npm.config.get('dry-run') || npm.config.get('long')
+ const showDiff = !npm.flatOptions.json &&
+ (npm.config.get('dry-run') || npm.config.get('long'))
const chalk = npm.chalk
depth({
@@ -221,7 +222,7 @@ const packagesChangedMessage = (npm, { added, removed, changed, audited }) => {
}
const packagesFundingMessage = (npm, { funding }) => {
- if (!funding) {
+ if (!funding || npm.global) {
return
}
diff --git a/deps/npm/man/man1/npm-access.1 b/deps/npm/man/man1/npm-access.1
index 435819623db2..ce8b4b2347e6 100644
--- a/deps/npm/man/man1/npm-access.1
+++ b/deps/npm/man/man1/npm-access.1
@@ -1,4 +1,4 @@
-.TH "NPM-ACCESS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ACCESS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-access\fR - Set access level on published packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-adduser.1 b/deps/npm/man/man1/npm-adduser.1
index 5cc628784241..99c40da90214 100644
--- a/deps/npm/man/man1/npm-adduser.1
+++ b/deps/npm/man/man1/npm-adduser.1
@@ -1,4 +1,4 @@
-.TH "NPM-ADDUSER" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ADDUSER" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-adduser\fR - Add a registry user account
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-approve-scripts.1 b/deps/npm/man/man1/npm-approve-scripts.1
index f874e752ab97..ea3b8559af31 100644
--- a/deps/npm/man/man1/npm-approve-scripts.1
+++ b/deps/npm/man/man1/npm-approve-scripts.1
@@ -1,4 +1,4 @@
-.TH "NPM-APPROVE-SCRIPTS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-APPROVE-SCRIPTS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-approve-scripts\fR - Approve install scripts for specific dependencies
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-audit.1 b/deps/npm/man/man1/npm-audit.1
index 8c9815292aee..d66317be2a68 100644
--- a/deps/npm/man/man1/npm-audit.1
+++ b/deps/npm/man/man1/npm-audit.1
@@ -1,4 +1,4 @@
-.TH "NPM-AUDIT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-AUDIT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-audit\fR - Run a security audit
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-bugs.1 b/deps/npm/man/man1/npm-bugs.1
index 0113cf310fdb..be2e0ec4073a 100644
--- a/deps/npm/man/man1/npm-bugs.1
+++ b/deps/npm/man/man1/npm-bugs.1
@@ -1,4 +1,4 @@
-.TH "NPM-BUGS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-BUGS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-bugs\fR - Report bugs for a package in a web browser
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-cache.1 b/deps/npm/man/man1/npm-cache.1
index 71eaeccf613d..08a904d5e7ac 100644
--- a/deps/npm/man/man1/npm-cache.1
+++ b/deps/npm/man/man1/npm-cache.1
@@ -1,4 +1,4 @@
-.TH "NPM-CACHE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-CACHE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-cache\fR - Manipulates packages cache
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ci.1 b/deps/npm/man/man1/npm-ci.1
index 2e544d6dfa80..b0611e9a121d 100644
--- a/deps/npm/man/man1/npm-ci.1
+++ b/deps/npm/man/man1/npm-ci.1
@@ -1,4 +1,4 @@
-.TH "NPM-CI" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-CI" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ci\fR - Clean install a project
.SS "Synopsis"
@@ -232,6 +232,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-completion.1 b/deps/npm/man/man1/npm-completion.1
index d5cefe61d0c7..b84d2dc1fd65 100644
--- a/deps/npm/man/man1/npm-completion.1
+++ b/deps/npm/man/man1/npm-completion.1
@@ -1,4 +1,4 @@
-.TH "NPM-COMPLETION" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-COMPLETION" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-completion\fR - Tab Completion for npm
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-config.1 b/deps/npm/man/man1/npm-config.1
index b0ef989fe726..2bbcce24963f 100644
--- a/deps/npm/man/man1/npm-config.1
+++ b/deps/npm/man/man1/npm-config.1
@@ -1,4 +1,4 @@
-.TH "NPM-CONFIG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-CONFIG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-config\fR - Manage the npm configuration files
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-dedupe.1 b/deps/npm/man/man1/npm-dedupe.1
index 1fa8e34027fb..f7f3cfc935ff 100644
--- a/deps/npm/man/man1/npm-dedupe.1
+++ b/deps/npm/man/man1/npm-dedupe.1
@@ -1,4 +1,4 @@
-.TH "NPM-DEDUPE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DEDUPE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-dedupe\fR - Reduce duplication in the package tree
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-deny-scripts.1 b/deps/npm/man/man1/npm-deny-scripts.1
index 70fb96d6fcd2..0477e41503b1 100644
--- a/deps/npm/man/man1/npm-deny-scripts.1
+++ b/deps/npm/man/man1/npm-deny-scripts.1
@@ -1,4 +1,4 @@
-.TH "NPM-DENY-SCRIPTS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DENY-SCRIPTS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-deny-scripts\fR - Deny install scripts for specific dependencies
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-deprecate.1 b/deps/npm/man/man1/npm-deprecate.1
index e07bd5829ef7..4caab6c3ad9a 100644
--- a/deps/npm/man/man1/npm-deprecate.1
+++ b/deps/npm/man/man1/npm-deprecate.1
@@ -1,4 +1,4 @@
-.TH "NPM-DEPRECATE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DEPRECATE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-deprecate\fR - Deprecate a version of a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-diff.1 b/deps/npm/man/man1/npm-diff.1
index 42c3903bd468..e2122d844c60 100644
--- a/deps/npm/man/man1/npm-diff.1
+++ b/deps/npm/man/man1/npm-diff.1
@@ -1,4 +1,4 @@
-.TH "NPM-DIFF" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DIFF" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-diff\fR - The registry diff command
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-dist-tag.1 b/deps/npm/man/man1/npm-dist-tag.1
index 8ebc625273cc..7a85fbab68d9 100644
--- a/deps/npm/man/man1/npm-dist-tag.1
+++ b/deps/npm/man/man1/npm-dist-tag.1
@@ -1,4 +1,4 @@
-.TH "NPM-DIST-TAG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DIST-TAG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-dist-tag\fR - Modify package distribution tags
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-docs.1 b/deps/npm/man/man1/npm-docs.1
index 26fa80d54d5d..ef586a86d27b 100644
--- a/deps/npm/man/man1/npm-docs.1
+++ b/deps/npm/man/man1/npm-docs.1
@@ -1,4 +1,4 @@
-.TH "NPM-DOCS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DOCS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-docs\fR - Open documentation for a package in a web browser
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-doctor.1 b/deps/npm/man/man1/npm-doctor.1
index f5b750fd6a3b..05c5c4d9dcc8 100644
--- a/deps/npm/man/man1/npm-doctor.1
+++ b/deps/npm/man/man1/npm-doctor.1
@@ -1,4 +1,4 @@
-.TH "NPM-DOCTOR" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DOCTOR" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-doctor\fR - Check the health of your npm environment
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-edit.1 b/deps/npm/man/man1/npm-edit.1
index 5055e6feaa5d..7bf09de5223b 100644
--- a/deps/npm/man/man1/npm-edit.1
+++ b/deps/npm/man/man1/npm-edit.1
@@ -1,4 +1,4 @@
-.TH "NPM-EDIT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EDIT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-edit\fR - Edit an installed package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-exec.1 b/deps/npm/man/man1/npm-exec.1
index 5ae0a77e2880..b3132e062c73 100644
--- a/deps/npm/man/man1/npm-exec.1
+++ b/deps/npm/man/man1/npm-exec.1
@@ -1,4 +1,4 @@
-.TH "NPM-EXEC" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EXEC" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-exec\fR - Run a command from a local or remote npm package
.SS "Synopsis"
@@ -181,6 +181,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-explain.1 b/deps/npm/man/man1/npm-explain.1
index 7869082b6c6f..1abb4a0e94da 100644
--- a/deps/npm/man/man1/npm-explain.1
+++ b/deps/npm/man/man1/npm-explain.1
@@ -1,4 +1,4 @@
-.TH "NPM-EXPLAIN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EXPLAIN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-explain\fR - Explain installed packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-explore.1 b/deps/npm/man/man1/npm-explore.1
index df1fd2dc6517..fc45ae27ae20 100644
--- a/deps/npm/man/man1/npm-explore.1
+++ b/deps/npm/man/man1/npm-explore.1
@@ -1,4 +1,4 @@
-.TH "NPM-EXPLORE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EXPLORE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-explore\fR - Browse an installed package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-find-dupes.1 b/deps/npm/man/man1/npm-find-dupes.1
index f1f3970dd1d7..5804305f900a 100644
--- a/deps/npm/man/man1/npm-find-dupes.1
+++ b/deps/npm/man/man1/npm-find-dupes.1
@@ -1,4 +1,4 @@
-.TH "NPM-FIND-DUPES" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-FIND-DUPES" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-find-dupes\fR - Find duplication in the package tree
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-fund.1 b/deps/npm/man/man1/npm-fund.1
index 88bfe299c31f..10eca78547ae 100644
--- a/deps/npm/man/man1/npm-fund.1
+++ b/deps/npm/man/man1/npm-fund.1
@@ -1,4 +1,4 @@
-.TH "NPM-FUND" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-FUND" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-fund\fR - Retrieve funding information
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-get.1 b/deps/npm/man/man1/npm-get.1
index 7982d28e324a..b67dfc6ed7e9 100644
--- a/deps/npm/man/man1/npm-get.1
+++ b/deps/npm/man/man1/npm-get.1
@@ -1,4 +1,4 @@
-.TH "NPM-GET" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-GET" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-get\fR - Get a value from the npm configuration
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-help-search.1 b/deps/npm/man/man1/npm-help-search.1
index e7c7d97ebcea..44c464dc229f 100644
--- a/deps/npm/man/man1/npm-help-search.1
+++ b/deps/npm/man/man1/npm-help-search.1
@@ -1,4 +1,4 @@
-.TH "NPM-HELP-SEARCH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-HELP-SEARCH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-help-search\fR - Search npm help documentation
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-help.1 b/deps/npm/man/man1/npm-help.1
index 7725a82d09c1..6c0dac1a9b93 100644
--- a/deps/npm/man/man1/npm-help.1
+++ b/deps/npm/man/man1/npm-help.1
@@ -1,4 +1,4 @@
-.TH "NPM-HELP" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-HELP" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-help\fR - Get help on npm
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-init.1 b/deps/npm/man/man1/npm-init.1
index bd984db7d203..3774607b93d3 100644
--- a/deps/npm/man/man1/npm-init.1
+++ b/deps/npm/man/man1/npm-init.1
@@ -1,4 +1,4 @@
-.TH "NPM-INIT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INIT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-init\fR - Create a package.json file
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-install-ci-test.1 b/deps/npm/man/man1/npm-install-ci-test.1
index b477b4a8b0eb..0725d13e7a9a 100644
--- a/deps/npm/man/man1/npm-install-ci-test.1
+++ b/deps/npm/man/man1/npm-install-ci-test.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL-CI-TEST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL-CI-TEST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install-ci-test\fR - Install a project with a clean slate and run tests
.SS "Synopsis"
@@ -180,6 +180,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-install-scripts.1 b/deps/npm/man/man1/npm-install-scripts.1
index b634903e3ecc..9d4076cd8fd3 100644
--- a/deps/npm/man/man1/npm-install-scripts.1
+++ b/deps/npm/man/man1/npm-install-scripts.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL-SCRIPTS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL-SCRIPTS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install-scripts\fR - Manage install-script approvals for dependencies
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-install-test.1 b/deps/npm/man/man1/npm-install-test.1
index d6774940ea2f..f552f5d39356 100644
--- a/deps/npm/man/man1/npm-install-test.1
+++ b/deps/npm/man/man1/npm-install-test.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL-TEST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL-TEST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install-test\fR - Install package(s) and run tests
.SS "Synopsis"
@@ -257,6 +257,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-install.1 b/deps/npm/man/man1/npm-install.1
index c6ca10ab642c..06e7759a10f1 100644
--- a/deps/npm/man/man1/npm-install.1
+++ b/deps/npm/man/man1/npm-install.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install\fR - Install a package
.SS "Synopsis"
@@ -647,6 +647,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-link.1 b/deps/npm/man/man1/npm-link.1
index ea482b872b86..9e03ea12635a 100644
--- a/deps/npm/man/man1/npm-link.1
+++ b/deps/npm/man/man1/npm-link.1
@@ -1,4 +1,4 @@
-.TH "NPM-LINK" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LINK" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-link\fR - Symlink a package folder
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ll.1 b/deps/npm/man/man1/npm-ll.1
index 136777491e0f..8fd1de7651e5 100644
--- a/deps/npm/man/man1/npm-ll.1
+++ b/deps/npm/man/man1/npm-ll.1
@@ -1,4 +1,4 @@
-.TH "NPM-LL" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LL" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ll\fR - List installed packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-login.1 b/deps/npm/man/man1/npm-login.1
index ecc47d745dee..aef0a9f0387a 100644
--- a/deps/npm/man/man1/npm-login.1
+++ b/deps/npm/man/man1/npm-login.1
@@ -1,4 +1,4 @@
-.TH "NPM-LOGIN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LOGIN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-login\fR - Login to a registry user account
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-logout.1 b/deps/npm/man/man1/npm-logout.1
index 22d86e96586e..941e7fdc0a51 100644
--- a/deps/npm/man/man1/npm-logout.1
+++ b/deps/npm/man/man1/npm-logout.1
@@ -1,4 +1,4 @@
-.TH "NPM-LOGOUT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LOGOUT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-logout\fR - Log out of the registry
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ls.1 b/deps/npm/man/man1/npm-ls.1
index 52224d908c20..96705c0c5aac 100644
--- a/deps/npm/man/man1/npm-ls.1
+++ b/deps/npm/man/man1/npm-ls.1
@@ -1,4 +1,4 @@
-.TH "NPM-LS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ls\fR - List installed packages
.SS "Synopsis"
@@ -20,7 +20,7 @@ Positional arguments are \fBname@version-range\fR identifiers, which will limit
.P
.RS 2
.nf
-npm@11.19.1 /path/to/npm
+npm@11.20.0 /path/to/npm
└─┬ init-package-json@0.0.4
└── promzard@0.1.5
.fi
diff --git a/deps/npm/man/man1/npm-org.1 b/deps/npm/man/man1/npm-org.1
index 4b7592722da4..38b8cdcf2454 100644
--- a/deps/npm/man/man1/npm-org.1
+++ b/deps/npm/man/man1/npm-org.1
@@ -1,4 +1,4 @@
-.TH "NPM-ORG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ORG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-org\fR - Manage orgs
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-outdated.1 b/deps/npm/man/man1/npm-outdated.1
index f83acac0d642..2995ee084341 100644
--- a/deps/npm/man/man1/npm-outdated.1
+++ b/deps/npm/man/man1/npm-outdated.1
@@ -1,4 +1,4 @@
-.TH "NPM-OUTDATED" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-OUTDATED" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-outdated\fR - Check for outdated packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-owner.1 b/deps/npm/man/man1/npm-owner.1
index 68a98e734ef5..a1644110b92b 100644
--- a/deps/npm/man/man1/npm-owner.1
+++ b/deps/npm/man/man1/npm-owner.1
@@ -1,4 +1,4 @@
-.TH "NPM-OWNER" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-OWNER" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-owner\fR - Manage package owners
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-pack.1 b/deps/npm/man/man1/npm-pack.1
index 58b82df26634..ea2ef9106377 100644
--- a/deps/npm/man/man1/npm-pack.1
+++ b/deps/npm/man/man1/npm-pack.1
@@ -1,4 +1,4 @@
-.TH "NPM-PACK" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PACK" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-pack\fR - Create a tarball from a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ping.1 b/deps/npm/man/man1/npm-ping.1
index 4df93fbd993a..d3590506a26e 100644
--- a/deps/npm/man/man1/npm-ping.1
+++ b/deps/npm/man/man1/npm-ping.1
@@ -1,4 +1,4 @@
-.TH "NPM-PING" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PING" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ping\fR - Ping npm registry
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-pkg.1 b/deps/npm/man/man1/npm-pkg.1
index ad11f73873aa..3c72c3739a52 100644
--- a/deps/npm/man/man1/npm-pkg.1
+++ b/deps/npm/man/man1/npm-pkg.1
@@ -1,4 +1,4 @@
-.TH "NPM-PKG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PKG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-pkg\fR - Manages your package.json
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-prefix.1 b/deps/npm/man/man1/npm-prefix.1
index 6c990176088b..1b5cf9e8e5b5 100644
--- a/deps/npm/man/man1/npm-prefix.1
+++ b/deps/npm/man/man1/npm-prefix.1
@@ -1,4 +1,4 @@
-.TH "NPM-PREFIX" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PREFIX" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-prefix\fR - Display prefix
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-profile.1 b/deps/npm/man/man1/npm-profile.1
index 0d5d54620f73..256f451dc450 100644
--- a/deps/npm/man/man1/npm-profile.1
+++ b/deps/npm/man/man1/npm-profile.1
@@ -1,4 +1,4 @@
-.TH "NPM-PROFILE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PROFILE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-profile\fR - Change settings on your registry profile
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-prune.1 b/deps/npm/man/man1/npm-prune.1
index 8f67ca9384f8..8c2823dc7a8b 100644
--- a/deps/npm/man/man1/npm-prune.1
+++ b/deps/npm/man/man1/npm-prune.1
@@ -1,4 +1,4 @@
-.TH "NPM-PRUNE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PRUNE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-prune\fR - Remove extraneous packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-publish.1 b/deps/npm/man/man1/npm-publish.1
index 4e738ab0bbd7..5b89d5a10208 100644
--- a/deps/npm/man/man1/npm-publish.1
+++ b/deps/npm/man/man1/npm-publish.1
@@ -1,4 +1,4 @@
-.TH "NPM-PUBLISH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PUBLISH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-publish\fR - Publish a package
.SS "Synopsis"
@@ -225,6 +225,8 @@ Type: Boolean
.P
When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from.
.P
+When the \fBprovenance-file\fR config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped.
+.P
This config cannot be used with: \fBprovenance-file\fR
.SS "\fBprovenance-file\fR"
.RS 0
@@ -237,6 +239,8 @@ Type: Path
.P
When publishing, the provenance bundle at the given path will be used.
.P
+This takes precedence over automatic provenance generation in trusted publishing flows.
+.P
This config cannot be used with: \fBprovenance\fR
.SS "See Also"
.RS 0
diff --git a/deps/npm/man/man1/npm-query.1 b/deps/npm/man/man1/npm-query.1
index 334fc20660e4..244e8b964694 100644
--- a/deps/npm/man/man1/npm-query.1
+++ b/deps/npm/man/man1/npm-query.1
@@ -1,4 +1,4 @@
-.TH "NPM-QUERY" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-QUERY" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-query\fR - Dependency selector query
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-rebuild.1 b/deps/npm/man/man1/npm-rebuild.1
index 6a09726529b4..3fb1df08bc54 100644
--- a/deps/npm/man/man1/npm-rebuild.1
+++ b/deps/npm/man/man1/npm-rebuild.1
@@ -1,4 +1,4 @@
-.TH "NPM-REBUILD" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-REBUILD" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-rebuild\fR - Rebuild a package
.SS "Synopsis"
@@ -115,6 +115,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-repo.1 b/deps/npm/man/man1/npm-repo.1
index 5ff08e9eeb4d..a68132d520b7 100644
--- a/deps/npm/man/man1/npm-repo.1
+++ b/deps/npm/man/man1/npm-repo.1
@@ -1,4 +1,4 @@
-.TH "NPM-REPO" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-REPO" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-repo\fR - Open package repository page in the browser
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-restart.1 b/deps/npm/man/man1/npm-restart.1
index d4f5f0d3df1f..8d1deb3ff11a 100644
--- a/deps/npm/man/man1/npm-restart.1
+++ b/deps/npm/man/man1/npm-restart.1
@@ -1,4 +1,4 @@
-.TH "NPM-RESTART" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-RESTART" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-restart\fR - Restart a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-root.1 b/deps/npm/man/man1/npm-root.1
index ecd0c64ef6bb..7090dca70da7 100644
--- a/deps/npm/man/man1/npm-root.1
+++ b/deps/npm/man/man1/npm-root.1
@@ -1,4 +1,4 @@
-.TH "NPM-ROOT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ROOT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-root\fR - Display npm root
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-run.1 b/deps/npm/man/man1/npm-run.1
index 8aadcceff7c1..fe72ce5905a0 100644
--- a/deps/npm/man/man1/npm-run.1
+++ b/deps/npm/man/man1/npm-run.1
@@ -1,4 +1,4 @@
-.TH "NPM-RUN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-RUN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-run\fR - Run arbitrary package scripts
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-sbom.1 b/deps/npm/man/man1/npm-sbom.1
index f694d642f9ad..531b802b6596 100644
--- a/deps/npm/man/man1/npm-sbom.1
+++ b/deps/npm/man/man1/npm-sbom.1
@@ -1,4 +1,4 @@
-.TH "NPM-SBOM" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SBOM" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-sbom\fR - Generate a Software Bill of Materials (SBOM)
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-search.1 b/deps/npm/man/man1/npm-search.1
index 969d0e784902..bf07a91bbc17 100644
--- a/deps/npm/man/man1/npm-search.1
+++ b/deps/npm/man/man1/npm-search.1
@@ -1,4 +1,4 @@
-.TH "NPM-SEARCH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SEARCH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-search\fR - Search for packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-set.1 b/deps/npm/man/man1/npm-set.1
index 4deaf8e01aca..4478b11a645f 100644
--- a/deps/npm/man/man1/npm-set.1
+++ b/deps/npm/man/man1/npm-set.1
@@ -1,4 +1,4 @@
-.TH "NPM-SET" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SET" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-set\fR - Set a value in the npm configuration
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-shrinkwrap.1 b/deps/npm/man/man1/npm-shrinkwrap.1
index 35caa20c3dc0..48949aa9d494 100644
--- a/deps/npm/man/man1/npm-shrinkwrap.1
+++ b/deps/npm/man/man1/npm-shrinkwrap.1
@@ -1,4 +1,4 @@
-.TH "NPM-SHRINKWRAP" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SHRINKWRAP" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-shrinkwrap\fR - Lock down dependency versions for publication
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-stage.1 b/deps/npm/man/man1/npm-stage.1
index 8c2016052130..0f2df23539ce 100644
--- a/deps/npm/man/man1/npm-stage.1
+++ b/deps/npm/man/man1/npm-stage.1
@@ -1,4 +1,4 @@
-.TH "NPM-STAGE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STAGE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-stage\fR - Stage packages for publishing
.SS "Synopsis"
@@ -101,7 +101,7 @@ npm stage publish
.RE
.SS "Flags"
.P
-| Flag | Default | Type | Description | | --- | --- | --- | --- | | \fB--tag\fR | "latest" | String | If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag. It is the tag added to the package@version specified in the \fBnpm dist-tag add\fR command, if no explicit tag is given. When used by the \fBnpm diff\fR command, this is the tag used to fetch the tarball that will be compared with the local files by default. If used in the \fBnpm publish\fR command, this is the tag that will be added to the package submitted to the registry. | | \fB--access\fR | 'public' for new packages, existing packages it will not change the current level | null, "restricted", "public", or "private" | If you do not want your scoped package to be publicly viewable (and installable) set \fB--access=restricted\fR. Unscoped packages cannot be set to \fBrestricted\fR. Note: This defaults to not changing the current access level for existing packages. Specifying a value of \fBrestricted\fR or \fBpublic\fR during publish will change the access for an existing package the same way that \fBnpm access set status\fR would. The value \fBprivate\fR is an alias for \fBrestricted\fR. | | \fB--dry-run\fR | false | Boolean | Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, \fBinstall\fR, \fBupdate\fR, \fBdedupe\fR, \fBuninstall\fR, as well as \fBpack\fR and \fBpublish\fR. Note: This is NOT honored by other network related commands, eg \fBdist-tags\fR, \fBowner\fR, etc. | | \fB--otp\fR | null | null or String | This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with \fBnpm access\fR. If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one. | | \fB--workspace\fR, \fB-w\fR | | String (can be set multiple times) | Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the \fBworkspace\fR config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the \fBnpm init\fR command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. | | \fB--workspaces\fR | null | null or Boolean | Set to true to run the command in the context of \fBall\fR configured workspaces. Explicitly setting this to false will cause commands like \fBinstall\fR to ignore workspaces altogether. When not set explicitly: - Commands that operate on the \fBnode_modules\fR tree (install, update, etc.) will link workspaces into the \fBnode_modules\fR folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, \fIunless\fR one or more workspaces are specified in the \fBworkspace\fR config. | | \fB--include-workspace-root\fR | false | Boolean | Include the workspace root when workspaces are enabled for a command. When false, specifying individual workspaces via the \fBworkspace\fR config, or all workspaces via the \fBworkspaces\fR flag, will cause npm to operate only on the specified workspaces, and not on the root project. | | \fB--provenance\fR | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. |
+| Flag | Default | Type | Description | | --- | --- | --- | --- | | \fB--tag\fR | "latest" | String | If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag. It is the tag added to the package@version specified in the \fBnpm dist-tag add\fR command, if no explicit tag is given. When used by the \fBnpm diff\fR command, this is the tag used to fetch the tarball that will be compared with the local files by default. If used in the \fBnpm publish\fR command, this is the tag that will be added to the package submitted to the registry. | | \fB--access\fR | 'public' for new packages, existing packages it will not change the current level | null, "restricted", "public", or "private" | If you do not want your scoped package to be publicly viewable (and installable) set \fB--access=restricted\fR. Unscoped packages cannot be set to \fBrestricted\fR. Note: This defaults to not changing the current access level for existing packages. Specifying a value of \fBrestricted\fR or \fBpublic\fR during publish will change the access for an existing package the same way that \fBnpm access set status\fR would. The value \fBprivate\fR is an alias for \fBrestricted\fR. | | \fB--dry-run\fR | false | Boolean | Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, \fBinstall\fR, \fBupdate\fR, \fBdedupe\fR, \fBuninstall\fR, as well as \fBpack\fR and \fBpublish\fR. Note: This is NOT honored by other network related commands, eg \fBdist-tags\fR, \fBowner\fR, etc. | | \fB--otp\fR | null | null or String | This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with \fBnpm access\fR. If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one. | | \fB--workspace\fR, \fB-w\fR | | String (can be set multiple times) | Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the \fBworkspace\fR config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the \fBnpm init\fR command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. | | \fB--workspaces\fR | null | null or Boolean | Set to true to run the command in the context of \fBall\fR configured workspaces. Explicitly setting this to false will cause commands like \fBinstall\fR to ignore workspaces altogether. When not set explicitly: - Commands that operate on the \fBnode_modules\fR tree (install, update, etc.) will link workspaces into the \fBnode_modules\fR folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, \fIunless\fR one or more workspaces are specified in the \fBworkspace\fR config. | | \fB--include-workspace-root\fR | false | Boolean | Include the workspace root when workspaces are enabled for a command. When false, specifying individual workspaces via the \fBworkspace\fR config, or all workspaces via the \fBworkspaces\fR flag, will cause npm to operate only on the specified workspaces, and not on the root project. | | \fB--provenance\fR | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. When the \fBprovenance-file\fR config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped. |
.SS "\fBnpm stage list\fR"
.P
List all staged package versions
diff --git a/deps/npm/man/man1/npm-star.1 b/deps/npm/man/man1/npm-star.1
index a2191c120e35..1c05090c3a22 100644
--- a/deps/npm/man/man1/npm-star.1
+++ b/deps/npm/man/man1/npm-star.1
@@ -1,4 +1,4 @@
-.TH "NPM-STAR" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STAR" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-star\fR - Mark your favorite packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-stars.1 b/deps/npm/man/man1/npm-stars.1
index aca98ed914a5..27ee3c674f0f 100644
--- a/deps/npm/man/man1/npm-stars.1
+++ b/deps/npm/man/man1/npm-stars.1
@@ -1,4 +1,4 @@
-.TH "NPM-STARS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STARS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-stars\fR - View packages marked as favorites
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-start.1 b/deps/npm/man/man1/npm-start.1
index d2f3b4d87cc8..17c42ab4023a 100644
--- a/deps/npm/man/man1/npm-start.1
+++ b/deps/npm/man/man1/npm-start.1
@@ -1,4 +1,4 @@
-.TH "NPM-START" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-START" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-start\fR - Start a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-stop.1 b/deps/npm/man/man1/npm-stop.1
index 7896dd6acd17..1d544669cbf0 100644
--- a/deps/npm/man/man1/npm-stop.1
+++ b/deps/npm/man/man1/npm-stop.1
@@ -1,4 +1,4 @@
-.TH "NPM-STOP" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STOP" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-stop\fR - Stop a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-team.1 b/deps/npm/man/man1/npm-team.1
index 21ccc530ad81..1d42f0f514c9 100644
--- a/deps/npm/man/man1/npm-team.1
+++ b/deps/npm/man/man1/npm-team.1
@@ -1,4 +1,4 @@
-.TH "NPM-TEAM" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TEAM" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-team\fR - Manage organization teams and team memberships
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-test.1 b/deps/npm/man/man1/npm-test.1
index 8cae879d8291..8136624750b3 100644
--- a/deps/npm/man/man1/npm-test.1
+++ b/deps/npm/man/man1/npm-test.1
@@ -1,4 +1,4 @@
-.TH "NPM-TEST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TEST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-test\fR - Test a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-token.1 b/deps/npm/man/man1/npm-token.1
index fc82daf8d0cf..dafb3148e684 100644
--- a/deps/npm/man/man1/npm-token.1
+++ b/deps/npm/man/man1/npm-token.1
@@ -1,4 +1,4 @@
-.TH "NPM-TOKEN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TOKEN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-token\fR - Manage your authentication tokens
.SS "Synopsis"
@@ -104,11 +104,11 @@ When creating a Granular Access Token with \fBnpm token create\fR, this limits t
.IP \(bu 4
Default: null
.IP \(bu 4
-Type: null, "read-only", "read-write", or "no-access"
+Type: null, "read-only", "read-write", "read-write-stage-only", or "no-access"
.RE 0
.P
-When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", or "no-access".
+When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", "read-write-stage-only", or "no-access". "read-write-stage-only" grants publish access that stages releases instead of publishing them directly.
.SS "\fBorgs-permission\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-trust.1 b/deps/npm/man/man1/npm-trust.1
index fce69eb33b75..87d202f3cef8 100644
--- a/deps/npm/man/man1/npm-trust.1
+++ b/deps/npm/man/man1/npm-trust.1
@@ -1,4 +1,4 @@
-.TH "NPM-TRUST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TRUST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-trust\fR - Manage trusted publishing relationships between packages and CI/CD providers
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-undeprecate.1 b/deps/npm/man/man1/npm-undeprecate.1
index 11f91ee9b913..6b3b29e1e560 100644
--- a/deps/npm/man/man1/npm-undeprecate.1
+++ b/deps/npm/man/man1/npm-undeprecate.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNDEPRECATE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNDEPRECATE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-undeprecate\fR - Undeprecate a version of a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-uninstall.1 b/deps/npm/man/man1/npm-uninstall.1
index b9ff997229dc..896258939adf 100644
--- a/deps/npm/man/man1/npm-uninstall.1
+++ b/deps/npm/man/man1/npm-uninstall.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNINSTALL" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNINSTALL" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-uninstall\fR - Remove a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-unpublish.1 b/deps/npm/man/man1/npm-unpublish.1
index 5bbb86e8c8f3..f99202071c02 100644
--- a/deps/npm/man/man1/npm-unpublish.1
+++ b/deps/npm/man/man1/npm-unpublish.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNPUBLISH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNPUBLISH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-unpublish\fR - Remove a package from the registry
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-unstar.1 b/deps/npm/man/man1/npm-unstar.1
index 0d0e2f2c9e6a..60bf9fea8bde 100644
--- a/deps/npm/man/man1/npm-unstar.1
+++ b/deps/npm/man/man1/npm-unstar.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNSTAR" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNSTAR" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-unstar\fR - Remove an item from your favorite packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-update.1 b/deps/npm/man/man1/npm-update.1
index 4f5e015b20d7..3e13678d0b98 100644
--- a/deps/npm/man/man1/npm-update.1
+++ b/deps/npm/man/man1/npm-update.1
@@ -1,4 +1,4 @@
-.TH "NPM-UPDATE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UPDATE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-update\fR - Update packages
.SS "Synopsis"
@@ -293,6 +293,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-version.1 b/deps/npm/man/man1/npm-version.1
index c15a0d19acfa..064e3a0b752b 100644
--- a/deps/npm/man/man1/npm-version.1
+++ b/deps/npm/man/man1/npm-version.1
@@ -1,4 +1,4 @@
-.TH "NPM-VERSION" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-VERSION" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-version\fR - Bump a package version
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-view.1 b/deps/npm/man/man1/npm-view.1
index b9210c424cd2..de67d3f900c7 100644
--- a/deps/npm/man/man1/npm-view.1
+++ b/deps/npm/man/man1/npm-view.1
@@ -1,4 +1,4 @@
-.TH "NPM-VIEW" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-VIEW" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-view\fR - View registry info
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-whoami.1 b/deps/npm/man/man1/npm-whoami.1
index 5d44c35a7f48..ddfde867876f 100644
--- a/deps/npm/man/man1/npm-whoami.1
+++ b/deps/npm/man/man1/npm-whoami.1
@@ -1,4 +1,4 @@
-.TH "NPM-WHOAMI" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-WHOAMI" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-whoami\fR - Display npm username
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm.1 b/deps/npm/man/man1/npm.1
index 25a9e19288c9..2f4b30a1f131 100644
--- a/deps/npm/man/man1/npm.1
+++ b/deps/npm/man/man1/npm.1
@@ -1,4 +1,4 @@
-.TH "NPM" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm\fR - javascript package manager
.SS "Synopsis"
@@ -12,7 +12,7 @@ npm
Note: This command is unaware of workspaces.
.SS "Version"
.P
-11.19.1
+11.20.0
.SS "Description"
.P
npm is the package manager for the Node JavaScript platform. It puts modules in place so that node can find them, and manages dependency conflicts intelligently.
diff --git a/deps/npm/man/man1/npx.1 b/deps/npm/man/man1/npx.1
index 39fcb358f7ce..a50bf96cf460 100644
--- a/deps/npm/man/man1/npx.1
+++ b/deps/npm/man/man1/npx.1
@@ -1,4 +1,4 @@
-.TH "NPX" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPX" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpx\fR - Run a command from a local or remote npm package
.SS "Synopsis"
diff --git a/deps/npm/man/man5/folders.5 b/deps/npm/man/man5/folders.5
index 7ec714295100..40aa02afd341 100644
--- a/deps/npm/man/man5/folders.5
+++ b/deps/npm/man/man5/folders.5
@@ -1,4 +1,4 @@
-.TH "FOLDERS" "5" "August 2026" "NPM@11.19.1" ""
+.TH "FOLDERS" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBFolders\fR - Folder structures used by npm
.SS "Description"
diff --git a/deps/npm/man/man5/install.5 b/deps/npm/man/man5/install.5
index b54f427c5da9..af38748dc564 100644
--- a/deps/npm/man/man5/install.5
+++ b/deps/npm/man/man5/install.5
@@ -1,4 +1,4 @@
-.TH "INSTALL" "5" "August 2026" "NPM@11.19.1" ""
+.TH "INSTALL" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBInstall\fR - Download and install node and npm
.SS "Description"
diff --git a/deps/npm/man/man5/npm-global.5 b/deps/npm/man/man5/npm-global.5
index 7ec714295100..40aa02afd341 100644
--- a/deps/npm/man/man5/npm-global.5
+++ b/deps/npm/man/man5/npm-global.5
@@ -1,4 +1,4 @@
-.TH "FOLDERS" "5" "August 2026" "NPM@11.19.1" ""
+.TH "FOLDERS" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBFolders\fR - Folder structures used by npm
.SS "Description"
diff --git a/deps/npm/man/man5/npm-json.5 b/deps/npm/man/man5/npm-json.5
index 4a79f2788851..41f16abf240c 100644
--- a/deps/npm/man/man5/npm-json.5
+++ b/deps/npm/man/man5/npm-json.5
@@ -1,4 +1,4 @@
-.TH "PACKAGE.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "PACKAGE.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBpackage.json\fR - Specifics of npm's package.json handling
.SS "Description"
diff --git a/deps/npm/man/man5/npm-shrinkwrap-json.5 b/deps/npm/man/man5/npm-shrinkwrap-json.5
index 1af7bf467c03..ec1a2cdcfab4 100644
--- a/deps/npm/man/man5/npm-shrinkwrap-json.5
+++ b/deps/npm/man/man5/npm-shrinkwrap-json.5
@@ -1,4 +1,4 @@
-.TH "NPM-SHRINKWRAP.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SHRINKWRAP.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-shrinkwrap.json\fR - A publishable lockfile
.SS "Description"
diff --git a/deps/npm/man/man5/npmrc.5 b/deps/npm/man/man5/npmrc.5
index 9d2361126088..d41c7e36a63f 100644
--- a/deps/npm/man/man5/npmrc.5
+++ b/deps/npm/man/man5/npmrc.5
@@ -1,4 +1,4 @@
-.TH ".NPMRC" "5" "August 2026" "NPM@11.19.1" ""
+.TH ".NPMRC" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fB.npmrc\fR - The npm config files
.SS "Description"
diff --git a/deps/npm/man/man5/package-json.5 b/deps/npm/man/man5/package-json.5
index 4a79f2788851..41f16abf240c 100644
--- a/deps/npm/man/man5/package-json.5
+++ b/deps/npm/man/man5/package-json.5
@@ -1,4 +1,4 @@
-.TH "PACKAGE.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "PACKAGE.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBpackage.json\fR - Specifics of npm's package.json handling
.SS "Description"
diff --git a/deps/npm/man/man5/package-lock-json.5 b/deps/npm/man/man5/package-lock-json.5
index ace3d4d69594..46d19e3b57a8 100644
--- a/deps/npm/man/man5/package-lock-json.5
+++ b/deps/npm/man/man5/package-lock-json.5
@@ -1,4 +1,4 @@
-.TH "PACKAGE-LOCK.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "PACKAGE-LOCK.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBpackage-lock.json\fR - A manifestation of the manifest
.SS "Description"
diff --git a/deps/npm/man/man7/config.7 b/deps/npm/man/man7/config.7
index 684663e33757..92fba90eec0a 100644
--- a/deps/npm/man/man7/config.7
+++ b/deps/npm/man/man7/config.7
@@ -1,4 +1,4 @@
-.TH "CONFIG" "7" "August 2026" "NPM@11.19.1" ""
+.TH "CONFIG" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBConfig\fR - About npm configuration
.SS "Description"
@@ -268,6 +268,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBallow-scripts-pending\fR"
.RS 0
.IP \(bu 4
@@ -1429,11 +1431,11 @@ When creating a Granular Access Token with \fBnpm token create\fR, grants the to
.IP \(bu 4
Default: null
.IP \(bu 4
-Type: null, "read-only", "read-write", or "no-access"
+Type: null, "read-only", "read-write", "read-write-stage-only", or "no-access"
.RE 0
.P
-When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", or "no-access".
+When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", "read-write-stage-only", or "no-access". "read-write-stage-only" grants publish access that stages releases instead of publishing them directly.
.SS "\fBparseable\fR"
.RS 0
.IP \(bu 4
@@ -1527,6 +1529,8 @@ Type: Boolean
.P
When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from.
.P
+When the \fBprovenance-file\fR config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped.
+.P
This config cannot be used with: \fBprovenance-file\fR
.SS "\fBprovenance-file\fR"
.RS 0
@@ -1539,6 +1543,8 @@ Type: Path
.P
When publishing, the provenance bundle at the given path will be used.
.P
+This takes precedence over automatic provenance generation in trusted publishing flows.
+.P
This config cannot be used with: \fBprovenance\fR
.SS "\fBproxy\fR"
.RS 0
diff --git a/deps/npm/man/man7/dependency-selectors.7 b/deps/npm/man/man7/dependency-selectors.7
index ec08ce0750b3..c81faa51b8cb 100644
--- a/deps/npm/man/man7/dependency-selectors.7
+++ b/deps/npm/man/man7/dependency-selectors.7
@@ -1,4 +1,4 @@
-.TH "SELECTORS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SELECTORS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBSelectors\fR - Dependency Selector Syntax & Querying
.SS "Description"
diff --git a/deps/npm/man/man7/developers.7 b/deps/npm/man/man7/developers.7
index aebb1f99a74a..8d240d09d82c 100644
--- a/deps/npm/man/man7/developers.7
+++ b/deps/npm/man/man7/developers.7
@@ -1,4 +1,4 @@
-.TH "DEVELOPERS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "DEVELOPERS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBDevelopers\fR - Developer guide
.SS "Description"
diff --git a/deps/npm/man/man7/logging.7 b/deps/npm/man/man7/logging.7
index 7fab6e089256..a0464b5231ca 100644
--- a/deps/npm/man/man7/logging.7
+++ b/deps/npm/man/man7/logging.7
@@ -1,4 +1,4 @@
-.TH "LOGGING" "7" "August 2026" "NPM@11.19.1" ""
+.TH "LOGGING" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBLogging\fR - Why, What & How we Log
.SS "Description"
diff --git a/deps/npm/man/man7/orgs.7 b/deps/npm/man/man7/orgs.7
index 975eded22dfc..7c01081ea037 100644
--- a/deps/npm/man/man7/orgs.7
+++ b/deps/npm/man/man7/orgs.7
@@ -1,4 +1,4 @@
-.TH "ORGANIZATIONS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "ORGANIZATIONS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBOrganizations\fR - Working with teams & organizations
.SS "Description"
diff --git a/deps/npm/man/man7/package-spec.7 b/deps/npm/man/man7/package-spec.7
index a68e9b8f7e74..9261a4edc18e 100644
--- a/deps/npm/man/man7/package-spec.7
+++ b/deps/npm/man/man7/package-spec.7
@@ -1,4 +1,4 @@
-.TH "SPEC" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SPEC" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBspec\fR - Package name specifier
.SS "Description"
diff --git a/deps/npm/man/man7/registry.7 b/deps/npm/man/man7/registry.7
index a91c60c14565..a529ad8c25da 100644
--- a/deps/npm/man/man7/registry.7
+++ b/deps/npm/man/man7/registry.7
@@ -1,4 +1,4 @@
-.TH "REGISTRY" "7" "August 2026" "NPM@11.19.1" ""
+.TH "REGISTRY" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBRegistry\fR - The JavaScript Package Registry
.SS "Description"
diff --git a/deps/npm/man/man7/removal.7 b/deps/npm/man/man7/removal.7
index bb4d7a8d4365..de3d5663c0ba 100644
--- a/deps/npm/man/man7/removal.7
+++ b/deps/npm/man/man7/removal.7
@@ -1,4 +1,4 @@
-.TH "REMOVAL" "7" "August 2026" "NPM@11.19.1" ""
+.TH "REMOVAL" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBRemoval\fR - Cleaning the slate
.SS "Synopsis"
diff --git a/deps/npm/man/man7/scope.7 b/deps/npm/man/man7/scope.7
index f2744feb1343..37b246569f7c 100644
--- a/deps/npm/man/man7/scope.7
+++ b/deps/npm/man/man7/scope.7
@@ -1,4 +1,4 @@
-.TH "SCOPE" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SCOPE" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBScope\fR - Scoped packages
.SS "Description"
diff --git a/deps/npm/man/man7/scripts.7 b/deps/npm/man/man7/scripts.7
index 4af3522042ba..d49e9941ba4c 100644
--- a/deps/npm/man/man7/scripts.7
+++ b/deps/npm/man/man7/scripts.7
@@ -1,4 +1,4 @@
-.TH "SCRIPTS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SCRIPTS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBScripts\fR - How npm handles the "scripts" field
.SS "Description"
diff --git a/deps/npm/man/man7/workspaces.7 b/deps/npm/man/man7/workspaces.7
index b31d897d2f3d..7e74e51a60e0 100644
--- a/deps/npm/man/man7/workspaces.7
+++ b/deps/npm/man/man7/workspaces.7
@@ -1,4 +1,4 @@
-.TH "WORKSPACES" "7" "August 2026" "NPM@11.19.1" ""
+.TH "WORKSPACES" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBWorkspaces\fR - Working with workspaces
.SS "Description"
diff --git a/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js b/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js
index 2f8ed83e1153..7ff7a21cf9b6 100644
--- a/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js
+++ b/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js
@@ -257,6 +257,22 @@ module.exports = cls => class IdealTreeBuilder extends cls {
this[_updateNames] = update.names
this[_updateAll] = update.all
+
+ // validates list of rm names, they must
+ // be dep names only, no semver ranges are supported
+ for (const name of options.rm || []) {
+ const spec = npa(name)
+ const validationError =
+ new TypeError(`Remove arguments must only contain package names, eg:
+ npm rm ${spec.name || ''}`)
+ validationError.code = 'ERMARGS'
+
+ // If they gave us anything other than a bare package name
+ if (spec.raw !== spec.name) {
+ throw validationError
+ }
+ }
+
// we prune by default unless explicitly set to boolean false
this.#prune = options.prune !== false
@@ -1473,6 +1489,16 @@ This is a one-time fix-up, please be patient...
if (!edge.to) {
if (!parentEdge) {
+ // the peer is missing from the virtual root; check the real tree before skipping.
+ // we can avoid a fetch for an optional peer, or a compatible provider, though
+ // an incompatible provider still has to be resolved here so that the
+ // optional peer set nests instead of displacing required peers.
+ if (edge.type === 'peerOptional') {
+ const current = node.parent.sourceReference.resolve(edge.name)
+ if (!current || current.satisfies(edge)) {
+ continue
+ }
+ }
// easy, just put the thing there
await this.#nodeFromEdge(edge, node.parent, null, required)
continue
diff --git a/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js b/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js
index 8c9b3fe118a8..629625f8e4f8 100644
--- a/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js
+++ b/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js
@@ -71,7 +71,7 @@ const isScriptAllowed = (node, policy) => {
const matches = (node, key, failClosed) => {
let parsed
try {
- parsed = npa(key)
+ parsed = npa(key, node?.root?.path)
} catch {
return false
}
@@ -328,8 +328,15 @@ const matchGit = (node, parsed) => {
}
const matchFileOrDir = (node, parsed) => {
+ // consistentResolve stores local sources as `file:` plus npa's absolute,
+ // platform-native fetchSpec.
+ const absoluteFileSpec = parsed.fetchSpec && `file:${parsed.fetchSpec}`
return resolvedSourceSpecs(node)
- .some(resolved => resolved === parsed.saveSpec || resolved === parsed.fetchSpec)
+ .some(resolved =>
+ resolved === parsed.saveSpec ||
+ resolved === parsed.fetchSpec ||
+ resolved === absoluteFileSpec
+ )
}
const matchRemote = (node, parsed) => {
@@ -381,4 +388,5 @@ module.exports.matches = matches
module.exports.isExactVersionDisjunction = isExactVersionDisjunction
module.exports.getTrustedRegistryIdentity = getTrustedRegistryIdentity
module.exports.resolvedSourceSpecs = resolvedSourceSpecs
+module.exports.matchFileOrDir = matchFileOrDir
module.exports.trustedDisplay = trustedDisplay
diff --git a/deps/npm/node_modules/@npmcli/arborist/package.json b/deps/npm/node_modules/@npmcli/arborist/package.json
index 1b71dfa4f124..8bd0ffeaa946 100644
--- a/deps/npm/node_modules/@npmcli/arborist/package.json
+++ b/deps/npm/node_modules/@npmcli/arborist/package.json
@@ -1,6 +1,6 @@
{
"name": "@npmcli/arborist",
- "version": "9.9.1",
+ "version": "9.9.2",
"description": "Manage node_modules trees",
"dependencies": {
"@gar/promise-retry": "^1.0.0",
diff --git a/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js b/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js
index 2bb1713458af..28be4cbd587d 100644
--- a/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js
+++ b/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js
@@ -258,6 +258,7 @@ const definitions = {
default: '',
type: [String, Array],
hint: '',
+ envExport: false,
description: `
Comma-separated list of packages whose install-time lifecycle scripts
(\`preinstall\`, \`install\`, \`postinstall\`, and \`prepare\` for
@@ -1880,6 +1881,10 @@ const definitions = {
description: `
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+
+ When the \`provenance-file\` config is set, it takes precedence and
+ automatic provenance generation (including via trusted publishing/OIDC)
+ is skipped.
`,
flatten,
}),
@@ -1890,6 +1895,9 @@ const definitions = {
exclusive: ['provenance'],
description: `
When publishing, the provenance bundle at the given path will be used.
+
+ This takes precedence over automatic provenance generation in trusted
+ publishing flows.
`,
flatten,
}),
@@ -2208,11 +2216,13 @@ const definitions = {
}),
'packages-and-scopes-permission': new Definition('packages-and-scopes-permission', {
default: null,
- type: [null, 'read-only', 'read-write', 'no-access'],
+ type: [null, 'read-only', 'read-write', 'read-write-stage-only', 'no-access'],
description: `
When creating a Granular Access Token with \`npm token create\`,
sets the permission level for packages and scopes. Options are
- "read-only", "read-write", or "no-access".
+ "read-only", "read-write", "read-write-stage-only", or "no-access".
+ "read-write-stage-only" grants publish access that stages releases
+ instead of publishing them directly.
`,
flatten,
}),
diff --git a/deps/npm/node_modules/@npmcli/config/package.json b/deps/npm/node_modules/@npmcli/config/package.json
index 360b0ab128a0..dcc39cef2ac9 100644
--- a/deps/npm/node_modules/@npmcli/config/package.json
+++ b/deps/npm/node_modules/@npmcli/config/package.json
@@ -1,6 +1,6 @@
{
"name": "@npmcli/config",
- "version": "10.12.0",
+ "version": "10.13.0",
"files": [
"bin/",
"lib/"
diff --git a/deps/npm/node_modules/libnpmdiff/package.json b/deps/npm/node_modules/libnpmdiff/package.json
index 8ce3729c325a..f9836046f44b 100644
--- a/deps/npm/node_modules/libnpmdiff/package.json
+++ b/deps/npm/node_modules/libnpmdiff/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmdiff",
- "version": "8.1.12",
+ "version": "8.1.13",
"description": "The registry diff",
"repository": {
"type": "git",
@@ -47,7 +47,7 @@
"tap": "^16.3.8"
},
"dependencies": {
- "@npmcli/arborist": "^9.9.1",
+ "@npmcli/arborist": "^9.9.2",
"@npmcli/installed-package-contents": "^4.0.0",
"binary-extensions": "^3.0.0",
"diff": "^8.0.2",
diff --git a/deps/npm/node_modules/libnpmexec/package.json b/deps/npm/node_modules/libnpmexec/package.json
index c76c285e56a4..116a7194043a 100644
--- a/deps/npm/node_modules/libnpmexec/package.json
+++ b/deps/npm/node_modules/libnpmexec/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmexec",
- "version": "10.3.2",
+ "version": "10.3.3",
"files": [
"bin/",
"lib/"
@@ -61,7 +61,7 @@
},
"dependencies": {
"@gar/promise-retry": "^1.0.0",
- "@npmcli/arborist": "^9.9.1",
+ "@npmcli/arborist": "^9.9.2",
"@npmcli/package-json": "^7.0.0",
"@npmcli/run-script": "^10.0.0",
"ci-info": "^4.0.0",
diff --git a/deps/npm/node_modules/libnpmfund/package.json b/deps/npm/node_modules/libnpmfund/package.json
index 88852421c70f..dcae1eb7476e 100644
--- a/deps/npm/node_modules/libnpmfund/package.json
+++ b/deps/npm/node_modules/libnpmfund/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmfund",
- "version": "7.0.26",
+ "version": "7.0.27",
"main": "lib/index.js",
"files": [
"bin/",
@@ -46,7 +46,7 @@
"tap": "^16.3.8"
},
"dependencies": {
- "@npmcli/arborist": "^9.9.1"
+ "@npmcli/arborist": "^9.9.2"
},
"engines": {
"node": "^20.17.0 || >=22.9.0"
diff --git a/deps/npm/node_modules/libnpmpack/package.json b/deps/npm/node_modules/libnpmpack/package.json
index 54c31fccd635..c4b3dc30d7e9 100644
--- a/deps/npm/node_modules/libnpmpack/package.json
+++ b/deps/npm/node_modules/libnpmpack/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmpack",
- "version": "9.1.13",
+ "version": "9.1.14",
"description": "Programmatic API for the bits behind npm pack",
"author": "GitHub Inc.",
"main": "lib/index.js",
@@ -37,7 +37,7 @@
"bugs": "https://github.com/npm/libnpmpack/issues",
"homepage": "https://npmjs.com/package/libnpmpack",
"dependencies": {
- "@npmcli/arborist": "^9.9.1",
+ "@npmcli/arborist": "^9.9.2",
"@npmcli/run-script": "^10.0.0",
"npm-package-arg": "^13.0.0",
"pacote": "^21.0.2"
diff --git a/deps/npm/node_modules/libnpmpublish/README.md b/deps/npm/node_modules/libnpmpublish/README.md
index 4daac34feaad..3abc096f6d88 100644
--- a/deps/npm/node_modules/libnpmpublish/README.md
+++ b/deps/npm/node_modules/libnpmpublish/README.md
@@ -53,11 +53,15 @@ A couple of options of note:
* `opts.provenance` - when running in a supported CI environment, will trigger
the generation of a signed provenance statement to be published alongside
- the package. Mutually exclusive with the `provenanceFile` option.
+ the package. Mutually exclusive with the `provenanceFile` option; providing
+ both will throw an `EUSAGE` error. In the npm CLI's trusted
+ publishing flows, automatic provenance generation is skipped when
+ `provenanceFile` is supplied.
* `opts.provenanceFile` - specifies the path to an externally-generated
provenance statement to be published alongside the package. Mutually
- exclusive with the `provenance` option. The specified file should be a
+ exclusive with the `provenance` option; providing both will throw an
+ `EUSAGE` error. The specified file should be a
[Sigstore Bundle](https://github.com/sigstore/protobuf-specs/blob/main/protos/sigstore_bundle.proto)
containing a [DSSE](https://github.com/secure-systems-lab/dsse)-packaged
provenance statement.
diff --git a/deps/npm/node_modules/libnpmpublish/lib/publish.js b/deps/npm/node_modules/libnpmpublish/lib/publish.js
index cfe85d2d29f5..2cfd54357295 100644
--- a/deps/npm/node_modules/libnpmpublish/lib/publish.js
+++ b/deps/npm/node_modules/libnpmpublish/lib/publish.js
@@ -134,6 +134,12 @@ const buildMetadata = async (registry, manifest, tarballData, spec, opts) => {
// Handle case where --provenance flag was set to true
let transparencyLogUrl
+ if (provenance === true && provenanceFile) {
+ throw Object.assign(
+ new Error('provenance and provenanceFile cannot be used together'),
+ { code: 'EUSAGE' }
+ )
+ }
if (provenance === true || provenanceFile) {
let provenanceBundle
const subject = {
diff --git a/deps/npm/node_modules/libnpmpublish/package.json b/deps/npm/node_modules/libnpmpublish/package.json
index 5b4ae66e5728..5b0ea2d47d2a 100644
--- a/deps/npm/node_modules/libnpmpublish/package.json
+++ b/deps/npm/node_modules/libnpmpublish/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmpublish",
- "version": "11.2.0",
+ "version": "11.2.1",
"description": "Programmatic API for the bits behind npm publish and unpublish",
"author": "GitHub Inc.",
"main": "lib/index.js",
diff --git a/deps/npm/package.json b/deps/npm/package.json
index a67f34569558..44b3ca520292 100644
--- a/deps/npm/package.json
+++ b/deps/npm/package.json
@@ -1,5 +1,5 @@
{
- "version": "11.19.1",
+ "version": "11.20.0",
"name": "npm",
"description": "a package manager for JavaScript",
"workspaces": [
@@ -52,8 +52,8 @@
},
"dependencies": {
"@isaacs/string-locale-compare": "^1.1.0",
- "@npmcli/arborist": "^9.9.1",
- "@npmcli/config": "^10.12.0",
+ "@npmcli/arborist": "^9.9.2",
+ "@npmcli/config": "^10.13.0",
"@npmcli/fs": "^5.0.0",
"@npmcli/map-workspaces": "^5.0.3",
"@npmcli/metavuln-calculator": "^9.0.3",
@@ -77,12 +77,12 @@
"is-cidr": "^6.0.4",
"json-parse-even-better-errors": "^5.0.0",
"libnpmaccess": "^10.0.3",
- "libnpmdiff": "^8.1.12",
- "libnpmexec": "^10.3.2",
- "libnpmfund": "^7.0.26",
+ "libnpmdiff": "^8.1.13",
+ "libnpmexec": "^10.3.3",
+ "libnpmfund": "^7.0.27",
"libnpmorg": "^8.0.1",
- "libnpmpack": "^9.1.13",
- "libnpmpublish": "^11.2.0",
+ "libnpmpack": "^9.1.14",
+ "libnpmpublish": "^11.2.1",
"libnpmsearch": "^9.0.1",
"libnpmteam": "^8.0.2",
"libnpmversion": "^8.0.4",
diff --git a/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs b/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs
index 1e2799652c91..25c42722d94f 100644
--- a/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs
+++ b/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs
@@ -327,7 +327,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. \`--ignore-scripts\` and
\`--dangerously-allow-all-scripts\` both override this setting.
-
+This value is not exported to the environment for child processes.
#### \`allow-scripts-pending\`
@@ -1529,11 +1529,14 @@ token access to all packages instead of limiting to specific packages.
#### \`packages-and-scopes-permission\`
* Default: null
-* Type: null, "read-only", "read-write", or "no-access"
+* Type: null, "read-only", "read-write", "read-write-stage-only", or
+ "no-access"
When creating a Granular Access Token with \`npm token create\`, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
@@ -1631,6 +1634,9 @@ Set to \`false\` to suppress the progress bar.
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the \`provenance-file\` config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
+
This config cannot be used with: \`provenance-file\`
#### \`provenance-file\`
@@ -1640,6 +1646,9 @@ This config cannot be used with: \`provenance-file\`
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
+
This config cannot be used with: \`provenance\`
#### \`proxy\`
@@ -6334,7 +6343,7 @@ Options:
[--name ] [--token-description ] [--expires ]
[--packages [--packages ...]] [--packages-all]
[--scopes [--scopes ...]] [--orgs [--orgs ...]]
-[--packages-and-scopes-permission ]
+[--packages-and-scopes-permission ]
[--orgs-permission ]
[--cidr [--cidr ...]] [--bypass-2fa] [--password ]
[--registry ] [--otp ] [--read-only]
diff --git a/deps/npm/test/fixtures/mock-oidc.js b/deps/npm/test/fixtures/mock-oidc.js
index d15d52c1b819..e2e11b27224b 100644
--- a/deps/npm/test/fixtures/mock-oidc.js
+++ b/deps/npm/test/fixtures/mock-oidc.js
@@ -101,7 +101,7 @@ const mockOidc = async (t, {
ciInfo.CIRCLE = CIRCLE
})
- const { npm, registry, joinedOutput, logs } = await loadNpmWithRegistry(t, {
+ const { npm, registry, joinedOutput, logs, prefix } = await loadNpmWithRegistry(t, {
config: {
loglevel: 'silly',
...config,
@@ -117,11 +117,12 @@ const mockOidc = async (t, {
})
if (mockGithubOidcOptions) {
- const { idToken, audience, statusCode = 200 } = mockGithubOidcOptions
+ const { idToken, audience, statusCode = 200, times = 1 } = mockGithubOidcOptions
const url = new URL(ACTIONS_ID_TOKEN_REQUEST_URL)
nock(url.origin)
.get(url.pathname)
.query({ audience })
+ .times(times)
.matchHeader('authorization', `Bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}`)
.matchHeader('accept', 'application/json')
.reply(statusCode, statusCode !== 500 ? { value: idToken } : { message: 'Internal Server Error' })
@@ -160,7 +161,7 @@ const mockOidc = async (t, {
})
}
- return { npm, joinedOutput, logs, ACTIONS_ID_TOKEN_REQUEST_URL }
+ return { npm, registry, prefix, joinedOutput, logs, ACTIONS_ID_TOKEN_REQUEST_URL }
}
const oidcPublishTest = (opts) => {
diff --git a/deps/npm/test/lib/commands/pack.js b/deps/npm/test/lib/commands/pack.js
index 21d961ebef6e..6f1f4453e337 100644
--- a/deps/npm/test/lib/commands/pack.js
+++ b/deps/npm/test/lib/commands/pack.js
@@ -256,7 +256,7 @@ t.test('invalid packument', async t => {
})
t.test('workspaces', async t => {
- const loadWorkspaces = (t) => loadMockNpm(t, {
+ const loadWorkspaces = (t, config = { workspaces: true }) => loadMockNpm(t, {
prefixDir: {
'package.json': JSON.stringify(
{
@@ -281,7 +281,7 @@ t.test('workspaces', async t => {
},
},
config: {
- workspaces: true,
+ ...config,
// TODO: this is a workaround for npm run test-all
// somehow leaking include-workspace-root
'include-workspace-root': false,
@@ -301,8 +301,10 @@ t.test('workspaces', async t => {
})
t.test('one workspace', async t => {
- const { npm, outputs } = await loadWorkspaces(t)
- await npm.exec('pack', ['workspace-a'])
+ const { npm, outputs } = await loadWorkspaces(t, {
+ workspace: ['workspace-a'],
+ })
+ await npm.exec('pack', [])
t.strictSame(outputs, ['workspace-a-1.0.0.tgz'])
})
diff --git a/deps/npm/test/lib/commands/publish.js b/deps/npm/test/lib/commands/publish.js
index 98576b08ea30..8b20c5671aad 100644
--- a/deps/npm/test/lib/commands/publish.js
+++ b/deps/npm/test/lib/commands/publish.js
@@ -3,6 +3,8 @@ const { loadNpmWithRegistry } = require('../../fixtures/mock-npm')
const { cleanZlib } = require('../../fixtures/clean-snapshot')
const pacote = require('pacote')
const Arborist = require('@npmcli/arborist')
+const npa = require('npm-package-arg')
+const ssri = require('ssri')
const path = require('node:path')
const fs = require('node:fs')
const { circleciIdToken, githubIdToken, gitlabIdToken, oidcPublishTest, mockOidc } = require('../../fixtures/mock-oidc')
@@ -1495,6 +1497,256 @@ t.test('oidc token exchange - provenance', (t) => {
},
}))
+ const provenanceFileSources = [
+ {
+ name: 'CLI config',
+ options: provenanceBundlePath => ({
+ config: {
+ 'provenance-file': provenanceBundlePath,
+ },
+ }),
+ },
+ {
+ // exercises Publish.#getManifest() and its flatten(filteredPublishConfig, opts)
+ // path: publishConfig must reach opts.provenanceFile before oidc() decides
+ // whether to enable automatic provenance
+ name: 'publishConfig',
+ options: provenanceBundlePath => ({
+ packageJson: {
+ publishConfig: {
+ 'provenance-file': provenanceBundlePath,
+ },
+ },
+ }),
+ },
+ ]
+
+ for (const { name, options } of provenanceFileSources) {
+ t.test(`${name} provenance-file takes precedence over OIDC auto-provenance`, async t => {
+ const bundleDir = t.testdir()
+ const provenanceBundlePath = path.join(
+ bundleDir,
+ 'provenance-bundle.json'
+ )
+ // holder so the libnpmpack mock can return the tarball computed below
+ const packMock = { tarballData: null }
+
+ const sourceOptions = options(provenanceBundlePath)
+
+ const { npm, registry, prefix, joinedOutput } = await mockOidc(t, {
+ oidcOptions: { github: true },
+ config: {
+ '//registry.npmjs.org/:_authToken': 'existing-fallback-token',
+ ...sourceOptions.config,
+ },
+ packageJson: sourceOptions.packageJson,
+ mockGithubOidcOptions: {
+ audience: 'npm:registry.npmjs.org',
+ idToken: githubPublicIdToken,
+ },
+ mockOidcTokenExchangeOptions: {
+ idToken: githubPublicIdToken,
+ body: {
+ token: 'exchange-token',
+ },
+ },
+ publishOptions: {
+ token: 'exchange-token',
+ noPut: true,
+ },
+ load: {
+ mocks: {
+ libnpmaccess: {
+ getVisibility: async () => ({ public: true }),
+ },
+ // publish a deterministic tarball so the bundle subject digest can match it
+ libnpmpack: async () => packMock.tarballData,
+ // libnpmpublish must be mocked as a module so its internal require of
+ // sigstore is intercepted: a user-supplied bundle is only verified,
+ // generation (attest) must never run
+ libnpmpublish: t.mock('libnpmpublish', {
+ 'libnpmpublish/lib/provenance': t.mock('libnpmpublish/lib/provenance', {
+ sigstore: {
+ verify: async () => {},
+ attest: async () => {
+ throw new Error('sigstore.attest must not be called when provenance-file is configured')
+ },
+ },
+ }),
+ }),
+ },
+ },
+ })
+
+ // compute the tarball integrity the same way libnpmpublish does so the
+ // provenance bundle subject matches the packed tarball
+ packMock.tarballData = await pacote.tarball(prefix, { Arborist })
+ const integrity = ssri.fromData(packMock.tarballData, { algorithms: ['sha512'] })
+ const spec = npa.resolve(pkg, '1.0.0')
+ const provenanceBundle = {
+ mediaType: 'application/vnd.dev.sigstore.bundle+json;version=0.2',
+ verificationMaterial: {
+ x509CertificateChain: {
+ certificates: [{ rawBytes: 'dGVzdA==' }],
+ },
+ tlogEntries: [],
+ },
+ dsseEnvelope: {
+ payload: Buffer.from(JSON.stringify({
+ _type: 'https://in-toto.io/Statement/v0.1',
+ subject: [
+ {
+ name: npa.toPurl(spec),
+ digest: { sha512: integrity.sha512[0].hexDigest() },
+ },
+ ],
+ predicateType: 'https://slsa.dev/provenance/v0.2',
+ predicate: {},
+ })).toString('base64'),
+ payloadType: 'application/vnd.in-toto+json',
+ signatures: [{
+ /* eslint-disable-next-line max-len */
+ sig: 'MEUCIQDqHtpkk1d0rMGLmf3qet9jLale3KVn8Pnywpwt7ln+9AIgG9CJvvUmyemhNYHz0DfJ4vMfKk1TMg+m3hR0mISXJos=',
+ keyid: '',
+ }],
+ },
+ }
+ fs.writeFileSync(provenanceBundlePath, JSON.stringify(provenanceBundle, null, 2))
+
+ let publishedBody
+ registry.nock
+ .put(`/${spec.escapedName}`, (body) => {
+ publishedBody = body
+ return true
+ })
+ .matchHeader('authorization', 'Bearer exchange-token')
+ // optional so a failed publish does not leave a pending mock behind
+ .optionally()
+ .reply(200, {})
+
+ // libnpmpublish checks package visibility itself before generating
+ // provenance; optional so it is only consumed if generation is attempted
+ registry.nock
+ .get(`/-/package/${spec.escapedName}/visibility`)
+ .optionally()
+ .reply(200, { public: true })
+
+ await npm.exec('publish', [])
+
+ t.match(joinedOutput(), '+ @npmcli/test-package@1.0.0')
+
+ const attachment =
+ publishedBody?._attachments[`${pkg}-1.0.0.sigstore`]
+
+ t.ok(attachment, 'published packument includes supplied provenance')
+ t.strictSame(
+ JSON.parse(attachment.data),
+ provenanceBundle,
+ 'published sigstore bundle is the user-supplied provenance file'
+ )
+ })
+ }
+
+ t.test('automatic provenance does not leak between workspace publishes', async t => {
+ const provenanceBundlePath = path.join(t.testdir(), 'provenance-bundle.json')
+ const autoPackage = 'workspace-auto-provenance'
+ const filePackage = 'workspace-file-provenance'
+ const publishCalls = []
+ const prefixDir = {
+ 'package.json': JSON.stringify({
+ name: 'workspace-root',
+ version: '1.0.0',
+ workspaces: [autoPackage, filePackage],
+ }),
+ [autoPackage]: {
+ 'package.json': JSON.stringify({
+ name: autoPackage,
+ version: '1.0.0',
+ }),
+ },
+ [filePackage]: {
+ 'package.json': JSON.stringify({
+ name: filePackage,
+ version: '1.0.0',
+ publishConfig: {
+ 'provenance-file': provenanceBundlePath,
+ },
+ }),
+ },
+ }
+
+ const { npm, registry } = await mockOidc(t, {
+ oidcOptions: { github: true },
+ packageName: autoPackage,
+ config: {
+ '//registry.npmjs.org/:_authToken': 'existing-fallback-token',
+ workspaces: true,
+ },
+ mockGithubOidcOptions: {
+ audience: 'npm:registry.npmjs.org',
+ idToken: githubPublicIdToken,
+ times: 2,
+ },
+ mockOidcTokenExchangeOptions: {
+ idToken: githubPublicIdToken,
+ body: {
+ token: 'exchange-token',
+ },
+ },
+ publishOptions: {
+ noPut: true,
+ },
+ load: {
+ prefixDir,
+ mocks: {
+ libnpmaccess: {
+ getVisibility: async () => ({ public: true }),
+ },
+ // mocked as a plain module so the publish options each workspace
+ // receives can be recorded verbatim
+ libnpmpublish: {
+ publish: async (manifest, _tarballData, opts) => {
+ publishCalls.push({
+ name: manifest.name,
+ provenance: opts.provenance,
+ provenanceFile: opts.provenanceFile,
+ })
+ },
+ },
+ },
+ },
+ })
+
+ registry.mockOidcTokenExchange({
+ packageName: filePackage,
+ idToken: githubPublicIdToken,
+ body: {
+ token: 'exchange-token',
+ },
+ })
+ registry.publish(filePackage, { noPut: true })
+
+ await npm.exec('publish', [])
+
+ t.strictSame(publishCalls, [
+ {
+ name: autoPackage,
+ provenance: true,
+ provenanceFile: null,
+ },
+ {
+ name: filePackage,
+ provenance: false,
+ provenanceFile: provenanceBundlePath,
+ },
+ ])
+ t.equal(
+ npm.config.isDefault('provenance'),
+ true,
+ 'automatic provenance does not mutate shared config'
+ )
+ })
+
const brokenJwts = [
'x.invalid-jwt.x',
'x.invalid-jwt.',
diff --git a/deps/npm/test/lib/commands/stage/list.js b/deps/npm/test/lib/commands/stage/list.js
index e66680db8277..ded079a5ab7b 100644
--- a/deps/npm/test/lib/commands/stage/list.js
+++ b/deps/npm/test/lib/commands/stage/list.js
@@ -15,6 +15,7 @@ const stageItems = [
actor: 'octocat',
actorType: 'user',
shasum: '4f7f5f1d5bcf2f72f6e4d6c4f3b2812d8a2f6c19',
+ status: 'validating',
},
{
id: 'f8e7a45b-7a5f-4f31-8e6d-9dd1c6ef38c0',
@@ -25,6 +26,7 @@ const stageItems = [
actor: 'npm-bot',
actorType: 'trusted automation',
shasum: '8eb3b4e9b6e3d0d2c86be1e6d4f43f4be62e80ad',
+ status: 'staged',
},
]
@@ -45,6 +47,9 @@ t.test('lists all staged packages', async t => {
t.match(out, 'package name: example-lib')
t.match(out, 'version: 1.2.3')
t.match(out, 'version: 0.4.0')
+ t.match(out, 'status: validating')
+ t.match(out, 'status: staged')
+ t.equal(out.match(/status:/g)?.length, 2, 'all server-provided statuses are shown')
})
t.test('lists with package filter', async t => {
@@ -80,6 +85,8 @@ t.test('lists with --json', async t => {
t.equal(out.length, 2)
t.equal(out[0].packageName, '@npmcli/example-package')
t.equal(out[0].id, '1de6f3db-2ed9-4d72-b3dd-8f0e2b474a2f', 'uuid id is not redacted')
+ t.equal(out[0].status, 'validating')
+ t.equal(out[1].status, 'staged')
})
t.test('shows message when no packages', async t => {
diff --git a/deps/npm/test/lib/commands/stage/view.js b/deps/npm/test/lib/commands/stage/view.js
index 604caf98fb23..36afc98b13d7 100644
--- a/deps/npm/test/lib/commands/stage/view.js
+++ b/deps/npm/test/lib/commands/stage/view.js
@@ -14,6 +14,7 @@ const stageItem = {
actor: 'octocat',
actorType: 'user',
shasum: '4f7f5f1d5bcf2f72f6e4d6c4f3b2812d8a2f6c19',
+ status: 'awaiting_approval',
}
t.test('views a staged package', async t => {
@@ -31,6 +32,7 @@ t.test('views a staged package', async t => {
t.match(out, /id:/)
t.match(out, 'package name: @npmcli/example-package')
t.match(out, 'version: 1.2.3')
+ t.match(out, 'status: awaiting_approval')
})
t.test('views with --json', async t => {
@@ -47,6 +49,7 @@ t.test('views with --json', async t => {
const out = JSON.parse(joinedOutput())
t.ok(out.id)
t.equal(out.packageName, '@npmcli/example-package')
+ t.equal(out.status, 'awaiting_approval')
})
t.test('throws usageError without stage-id', async t => {
diff --git a/deps/npm/test/lib/commands/token.js b/deps/npm/test/lib/commands/token.js
index 34297a923c89..41ca9395375a 100644
--- a/deps/npm/test/lib/commands/token.js
+++ b/deps/npm/test/lib/commands/token.js
@@ -475,3 +475,115 @@ t.test('token create invalid cidr', async t => {
message: 'CIDR whitelist contains invalid CIDR entry: apple/cider',
})
})
+
+t.test('token create stage-only produces stage-only policy and no warning', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'stage-only-token',
+ password: 'test-password',
+ 'packages-and-scopes-permission': 'read-write-stage-only',
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'stage-only-token',
+ password: 'test-password',
+ packages_and_scopes_permission: 'read-write-stage-only',
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.strictSame(logs.warn, [], 'no deprecation warning for stage-only tokens')
+})
+
+t.test('token create read-write warns about direct-publish', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'rw-token',
+ password: 'test-password',
+ 'packages-and-scopes-permission': 'read-write',
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'rw-token',
+ password: 'test-password',
+ packages_and_scopes_permission: 'read-write',
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.match(logs.warn, [/publish directly to the registry/], 'warns about direct-publish token')
+ t.match(logs.warn, [/read-write-stage-only/], 'warning points to stage-only tokens')
+ t.match(logs.warn, [/https:\/\/gh\.io\/bypass-2fa-tokens-no-longer-publish/], 'warning includes the docs link')
+})
+
+t.test('token create bypass-2fa alone does not warn', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'bypass-token',
+ password: 'test-password',
+ 'bypass-2fa': true,
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'bypass-token',
+ password: 'test-password',
+ bypass_2fa: true,
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.strictSame(logs.warn, [], 'bypass-2fa alone grants no publish capability, so no warning')
+})
+
+t.test('token create read-write with bypass-2fa warns about direct-publish', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'rw-bypass-token',
+ password: 'test-password',
+ 'packages-and-scopes-permission': 'read-write',
+ 'bypass-2fa': true,
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'rw-bypass-token',
+ password: 'test-password',
+ packages_and_scopes_permission: 'read-write',
+ bypass_2fa: true,
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.match(logs.warn, [/publish directly to the registry/], 'warns for read-write automation publish token')
+})
diff --git a/deps/npm/test/lib/commands/uninstall.js b/deps/npm/test/lib/commands/uninstall.js
index 049bf2da8b1c..0302aa5bac30 100644
--- a/deps/npm/test/lib/commands/uninstall.js
+++ b/deps/npm/test/lib/commands/uninstall.js
@@ -143,6 +143,34 @@ t.test('remove multiple installed libs', async t => {
t.throws(() => fs.statSync(b), 'should have removed b package from nm')
})
+t.test('rejects an arg with a version spec', async t => {
+ const { uninstall } = await mockNpm(t, {
+ prefixDir: {
+ 'package.json': JSON.stringify({
+ name: 'test-rm-version-spec',
+ version: '1.0.0',
+ dependencies: {
+ foo: '*',
+ },
+ }),
+ node_modules: {
+ foo: {
+ 'package.json': JSON.stringify({
+ name: 'foo',
+ version: '1.0.0',
+ }),
+ },
+ },
+ },
+ })
+
+ await t.rejects(
+ uninstall(['foo@1']),
+ { code: 'ERMARGS', message: /npm rm foo/ },
+ 'should throw ERMARGS instead of silently no-oping'
+ )
+})
+
t.test('no args local', async t => {
const { uninstall } = await mockNpm(t)
diff --git a/deps/npm/test/lib/utils/allow-scripts-prune.js b/deps/npm/test/lib/utils/allow-scripts-prune.js
index 880b1dfe3437..ea39bc6ecffc 100644
--- a/deps/npm/test/lib/utils/allow-scripts-prune.js
+++ b/deps/npm/test/lib/utils/allow-scripts-prune.js
@@ -1,4 +1,5 @@
const t = require('tap')
+const path = require('node:path')
const { classifyUnusedEntries } = require('../../../lib/utils/allow-scripts-prune.js')
// Minimal registry node: `matches` derives name/version from the resolved URL.
@@ -29,6 +30,26 @@ t.test('keeps entries that match an installed package with scripts', t => {
t.end()
})
+t.test('keeps a local file key matching its absolute resolved source', t => {
+ const rootPath = path.resolve('project')
+ const key = `file:${path.resolve(rootPath, 'local.tgz')}`
+ const local = {
+ name: 'local',
+ version: '1.0.0',
+ resolved: key,
+ root: { path: rootPath },
+ isRegistryDependency: false,
+ }
+ const { remaining, removed } = classifyUnusedEntries(
+ { [key]: true },
+ [{ node: local, hasScripts: true }]
+ )
+
+ t.same(remaining, { [key]: true })
+ t.same(removed, [])
+ t.end()
+})
+
t.test('removes entries for packages no longer installed', t => {
const { remaining, removed } = classifyUnusedEntries(
{ canvas: true, gone: true },
diff --git a/deps/npm/test/lib/utils/allow-scripts-writer.js b/deps/npm/test/lib/utils/allow-scripts-writer.js
index 8edf25be3079..f13389c8c258 100644
--- a/deps/npm/test/lib/utils/allow-scripts-writer.js
+++ b/deps/npm/test/lib/utils/allow-scripts-writer.js
@@ -1,8 +1,10 @@
const t = require('tap')
const path = require('node:path')
+const isScriptAllowed = require('../../../workspaces/arborist/lib/script-allowed.js')
const {
applyApprovalForPackage,
applyDenyForPackage,
+ keyTargetsNode,
nameKeyFor,
versionedKeyFor,
isSingleVersionPin,
@@ -379,6 +381,21 @@ t.test('applyApprovalForPackage — file dep uses resolved as both keys', async
t.strictSame(allowScripts, { 'file:../local': true })
})
+t.test('versionedKeyFor — local file key round-trips through policy matching', async t => {
+ const rootPath = path.resolve('project')
+ const local = {
+ name: 'local',
+ packageName: 'local',
+ version: '1.0.0',
+ resolved: `file:${path.resolve(rootPath, 'local.tgz')}`,
+ root: { path: rootPath },
+ isRegistryDependency: false,
+ }
+ const key = versionedKeyFor(local)
+
+ t.equal(isScriptAllowed(local, { [key]: true }), true)
+})
+
t.test('applyApprovalForPackage — empty nodes returns unchanged', async t => {
const { allowScripts, changes } = applyApprovalForPackage({ x: true }, [], { pin: true })
t.strictSame(allowScripts, { x: true })
@@ -493,6 +510,29 @@ t.test('applyApprovalForPackage — file dep with deny entry blocks approval', a
t.match(warning, /denied|versioned deny/)
})
+t.test('applyApprovalForPackage — relative file deny matches absolute resolved', async t => {
+ const rootPath = path.resolve('project')
+ const resolved = `file:${path.resolve(rootPath, 'local.tgz')}`
+ const local = {
+ name: 'local',
+ packageName: 'local',
+ version: '1.0.0',
+ resolved,
+ root: { path: rootPath },
+ isRegistryDependency: false,
+ }
+ const existing = { 'file:local.tgz': false }
+ const { allowScripts, changes, warning } = applyApprovalForPackage(
+ existing,
+ [local],
+ { pin: true }
+ )
+
+ t.strictSame(allowScripts, existing)
+ t.strictSame(changes, [])
+ t.match(warning, /denied|versioned deny/)
+})
+
t.test('applyApprovalForPackage — remote tarball deny blocks approval', async t => {
const remote = { name: 'pkg', packageName: 'pkg', version: '1.0.0', resolved: 'https://example.com/pkg.tgz' }
const { warning } = applyApprovalForPackage(
@@ -501,6 +541,7 @@ t.test('applyApprovalForPackage — remote tarball deny blocks approval', async
{ pin: true }
)
t.match(warning, /denied|versioned deny/)
+ t.equal(keyTargetsNode('https://example.com/other.tgz', remote), false)
})
t.test('applyApprovalForPackage — no-pin with no name produces no-op', async t => {
diff --git a/deps/npm/test/lib/utils/key-values.js b/deps/npm/test/lib/utils/key-values.js
index 5e61f9e55fe5..f162346eab4b 100644
--- a/deps/npm/test/lib/utils/key-values.js
+++ b/deps/npm/test/lib/utils/key-values.js
@@ -76,6 +76,40 @@ t.test('logStageItem without actorType shows actor alone', async t => {
t.notMatch(out, /\(/)
})
+t.test('logStageItem shows status returned by the server', async t => {
+ const { joinedOutput } = await loadMockNpm(t)
+ const chalk = { cyan: v => v, green: v => v }
+ const item = {
+ id: 'abc',
+ packageName: 'pkg',
+ version: '1.0.0',
+ tag: 'latest',
+ createdAt: '2026-01-01',
+ actor: 'user',
+ shasum: 'sha1',
+ }
+
+ logStageItem({ ...item, status: 'awaiting_approval' }, { chalk })
+ t.match(joinedOutput(), /status: awaiting_approval/)
+})
+
+t.test('logStageItem omits missing status', async t => {
+ const { joinedOutput } = await loadMockNpm(t)
+ const chalk = { cyan: v => v, green: v => v }
+ const item = {
+ id: 'abc',
+ packageName: 'pkg',
+ version: '1.0.0',
+ tag: 'latest',
+ createdAt: '2026-01-01',
+ actor: 'user',
+ shasum: 'sha1',
+ }
+
+ logStageItem(item, { chalk })
+ t.notMatch(joinedOutput(), /status:/)
+})
+
t.test('logObject with all values skipped produces no output', async t => {
const { joinedOutput } = await loadMockNpm(t)
const chalk = { cyan: v => v, green: v => v }
diff --git a/deps/npm/test/lib/utils/reify-output.js b/deps/npm/test/lib/utils/reify-output.js
index ee9201482a75..17939c712af2 100644
--- a/deps/npm/test/lib/utils/reify-output.js
+++ b/deps/npm/test/lib/utils/reify-output.js
@@ -128,6 +128,35 @@ t.test('no message when funding config is false', async t => {
t.notMatch(out, 'looking for funding', 'should not print funding info')
})
+t.test('no message when installing globally', async t => {
+ const out = await mockReify(t, {
+ actualTree: {
+ name: 'foo',
+ package: {
+ name: 'foo',
+ version: '1.0.0',
+ },
+ edgesOut: new Map([
+ ['bar', {
+ to: {
+ name: 'bar',
+ package: {
+ name: 'bar',
+ version: '1.0.0',
+ funding: { type: 'foo', url: 'http://example.com' },
+ },
+ },
+ }],
+ ]),
+ },
+ diff: {
+ children: [],
+ },
+ }, { global: true })
+
+ t.notMatch(out, 'looking for funding', 'should not print funding info')
+})
+
t.test('print appropriate message for many packages', async t => {
const out = await mockReify(t, {
actualTree: {
@@ -440,6 +469,53 @@ t.test('prints dedupe difference on dry-run', async t => {
t.matchSnapshot(out, 'diff table')
})
+t.test('prints only json for dry-run and long', async t => {
+ for (const flag of ['dry-run', 'long']) {
+ await t.test(flag, async t => {
+ const out = await mockReify(t, {
+ actualTree: {
+ inventory: {
+ has: () => true,
+ },
+ children: [],
+ },
+ diff: {
+ children: [
+ {
+ action: 'ADD',
+ ideal: {
+ path: 'test/foo',
+ name: 'foo',
+ package: { version: '1.0.0' },
+ },
+ },
+ ],
+ },
+ }, {
+ [flag]: true,
+ json: true,
+ })
+
+ t.strictSame(JSON.parse(out), {
+ add: [
+ {
+ name: 'foo',
+ version: '1.0.0',
+ path: 'test/foo',
+ },
+ ],
+ added: 1,
+ audited: 0,
+ change: [],
+ changed: 0,
+ funding: 0,
+ remove: [],
+ removed: 0,
+ })
+ })
+ }
+})
+
t.test('prints dedupe difference on long', async t => {
const mock = {
actualTree: {
diff --git a/deps/npm/test/lib/utils/resolve-allow-scripts.js b/deps/npm/test/lib/utils/resolve-allow-scripts.js
index a27d600d98f0..650094ba170b 100644
--- a/deps/npm/test/lib/utils/resolve-allow-scripts.js
+++ b/deps/npm/test/lib/utils/resolve-allow-scripts.js
@@ -86,6 +86,22 @@ t.test('--allow-scripts CLI flag is rejected in project-scoped installs', async
)
})
+t.test('allow-scripts environment policy is rejected in project-scoped installs', async t => {
+ const mock = await mockNpm(t, {
+ prefixDir: {
+ 'package.json': JSON.stringify({ name: 'p' }),
+ },
+ globals: {
+ 'process.env.npm_config_allow_scripts': 'canvas',
+ },
+ })
+ const resolveAllowScripts = loadResolver(t)
+ await t.rejects(
+ resolveAllowScripts(mock.npm),
+ { code: 'EALLOWSCRIPTS', message: /--allow-scripts is not allowed/ }
+ )
+})
+
t.test('--allow-scripts CLI flag is accepted in global installs (RFC layer 1 wins)', async t => {
const mock = await mockNpm(t, {
prefixDir: {