- 
                Notifications
    You must be signed in to change notification settings 
- Fork 132
chore(deps): update npm to v11 #1358
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
66c4631    to
    cf9f370      
    Compare
  
    cf9f370    to
    e3f4991      
    Compare
  
    e3f4991    to
    d6376e7      
    Compare
  
    d6376e7    to
    1a56d46      
    Compare
  
    1a56d46    to
    605c43e      
    Compare
  
    605c43e    to
    b8b2b53      
    Compare
  
    5a06a09    to
    68e1813      
    Compare
  
    | Preview for this PR was built for commit  | 
68e1813    to
    5481ad7      
    Compare
  
    | Preview for this PR was built for commit  | 
5481ad7    to
    5fe371e      
    Compare
  
    There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Comment bugbot run to trigger another review on this PR
| "algoliasearch": "^5.19.0", | ||
| "algoliasearch-helper": "^3.22.6", | ||
| "axios": "^1.11.0", | ||
| "axios": "^1.7.9", | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bug: Axios Downgrade Causes Security Vulnerabilities
The axios dependency in the apify-docs-theme workspace was unexpectedly downgraded from ^1.11.0 to ^1.7.9. This is an unintended side effect of updating npm from v10 to v11, likely due to different dependency resolution behavior. This downgrade could reintroduce security vulnerabilities, bugs, or compatibility issues.
Locations (1)
| Preview for this PR was built for commit  | 
5fe371e    to
    6de9779      
    Compare
  
    | Preview for this PR was built for commit  | 
24f3efa    to
    d4a6e0b      
    Compare
  
    | Preview for this PR was built for commit  | 
    
      
        1 similar comment
      
    
  
    | Preview for this PR was built for commit  | 
d4a6e0b    to
    3579185      
    Compare
  
    | Preview for this PR was built for commit  | 
3579185    to
    795a755      
    Compare
  
    | Preview for this PR was built for commit  | 
795a755    to
    4c1c62c      
    Compare
  
    | Preview for this PR was built for commit  | 
4c1c62c    to
    e196c09      
    Compare
  
    | Preview for this PR was built for commit  | 
e196c09    to
    7ed1bc3      
    Compare
  
    | Preview for this PR was built for commit  | 
| Preview for this PR was built for commit  | 
5bfbc38    to
    c2e5bb4      
    Compare
  
    | Preview for this PR was built for commit  | 
c2e5bb4    to
    9f99ea7      
    Compare
  
    | Preview for this PR was built for commit  | 
9f99ea7    to
    6d542e2      
    Compare
  
    | Preview for this PR was built for commit  | 
6d542e2    to
    29ea010      
    Compare
  
    | Preview for this PR was built for commit  | 
29ea010    to
    8e487f4      
    Compare
  
    | Preview for this PR was built for commit  | 
b749203    to
    ea71462      
    Compare
  
    | Preview for this PR was built for commit  | 
| Preview for this PR was built for commit  | 
edaeca6    to
    9ead362      
    Compare
  
    | Preview for this PR was built for commit  | 
| Preview for this PR was built for commit  | 
9ead362    to
    04ddc36      
    Compare
  
    | Preview for this PR was built for commit  | 
04ddc36    to
    0078417      
    Compare
  
    | Preview for this PR was built for commit  | 
0078417    to
    ea671d9      
    Compare
  
    | Preview for this PR was built for commit  | 
ea671d9    to
    86c706c      
    Compare
  
    | Preview for this PR was built for commit  | 
86c706c    to
    ba04e41      
    Compare
  
    | Preview for this PR was built for commit  | 
This PR contains the following updates:
10.9.2->11.6.2Release Notes
npm/cli (npm)
v11.6.2Compare Source
Bug Fixes
c54d1e9#8633 progress bar code cleanup (#8633) (@wraithgar)d352e27#8629 do not redact notice logs going to stdout (#8629) (@wraithgar)5ac3678#8617 spelling in ./lib and ./test/lib (#8617) (@jsoref)9197995#8619 spelling (#8619) (@jsoref)dd884e3#8618 spelling (#8618) (@jsoref)f6028e6#8614 skip redacting urls meant for opening by the user (#8614) (@wraithgar, @jolyndenning)54fd27f#8602 refactor node.ideallyInert to node.inert (#8602) (@liamcmitchell)79e3c1e#8593 use @npmcli/package-json to normalize package data (@wraithgar)Documentation
0469c5e#8639 rewrap markdown (#8639) (@jsoref)9ceb9c1#8636 rewrap markdown (#8636) (@jsoref)6324370#8616 fix spelling (#8616) (@jsoref)1b0429a#8607 Fix spelling (#8607) (@jsoref)7fbe07a#8603 clean up deprecatednpm accesscommands (#8603) (@jsoref)Dependencies
fa7cc6f#8662ci-info@4.3.1(#8662)b05461b#8663@sigstore/sign@4.0.1(#8663)c31de22#8661 downgrade ci-info to 4.3.0 (#8661) (@wraithgar)c5191b5#8659ci-info@4.3.1f255c92#8659hosted-git-info@9.0.2bdaf323#8659is-cidr@6.0.1a33f106#8659lru-cache@11.2.28044e07#8659npm-package-arg@13.0.1f577504#8659npm-packlist@10.0.29aa4fa6#8659semver@7.7.3fe9484a#8593 remove normalize-package-dataChores
b3409f4#8659 dev dependency updates (@wraithgar)e8de81b#8643 Add automatically generated annotation to dependencies.md (#8643) (@jsoref)67cfaf3#8627 fix spelling: different (#8627) (@jsoref)17ddc0d#8622 fix spelling (#8622) (@jsoref)c3e1790#8605 Remove reference to nonexistent calendar (#8605) (@jsoref)ac9143e#8604 Improve link accessibility for screen reader users (#8604) (@jsoref)62d73e7#8601 remove references to benchmarks workflow (#8601) (@jsoref)bb4b739#8598 remove stale comment (#8598) (@jsoref)f73e65d#8592 fix build url code for remark-github@12 (#8592) (@wraithgar)@npmcli/arborist@9.1.6@npmcli/config@10.4.2libnpmaccess@10.0.3libnpmdiff@8.0.9libnpmexec@10.1.8libnpmfund@7.0.9libnpmpack@9.0.9libnpmpublish@11.1.2v11.6.1Compare Source
Bug Fixes
d389614#8579 corrects peer dependency flag propagation (@owlstronaut)5db81c3#8512 allow concurrent non-local npx calls (#8512) (@jenseng, @wraithgar)Documentation
7a09902#8582 bring back certfile (#8582) (@jenseng)Dependencies
849dcb6#8589tar@7.5.1(#8589)ea15731#8576binary-extensions@3.1.00f41bac#8576tiny-relative-date@2.0.207bf540#8576is-cidr@6.0.0ef87ec6#8576diff@8.0.248285e0#8576 add fdir, isexe, and picomatch to node_modules099238a#8576fdir@6.5.06e4d673#8576isexe@3.1.109a7494#8576supports-color@10.2.2c5157c9#8576chalk@5.6.246035db#8576debug@4.4.35f6664b#8576spdx-license-ids@3.0.225516583#8576socks@2.8.76a392f3#8576tinyglobby@0.2.159519f18#8576npm-install-checks@7.1.234bafd1#8576node-gyp@11.4.2dfd034e#8576@npmcli/promise-spawn@8.0.3d4eef14#8576rimraf@6.0.1566f1b7#8576minimatch@10.0.3ac33497#8576mkdirp@3.0.11676626#8576glob@11.0.3817f0b1#8576ignore-walk@8.0.079a4e67#8576minizlib@3.0.238fa2c2#8576negotiator@1.0.024252a1#8576@npmcli/agent@4.0.0ea7ca5f#8576lru-cache@11.2.1521823b#8576@npmcli/git@7.0.0bf6b686#8576npm-package-arg@13.0.09392488#8576npm-package-manifest@11.0.10082083#8576normalize-package-data@8.0.0633c4ed#8576hosted-git-info@9.0.066f64eb#8576make-fetch-happen@15.0.21f85f94#8576@sigstore/tuf@4.0.0a2bdecc#8576sigstore@4.0.01149971#8576npm-registry-fetch@19.0.0b5bd5e3#8576npm-profile@12.0.06221e27#8576@npmcli/metavuln-calculator@9.0.2da81a37#8576cacache@20.0.16b4c5f9#8576@npmcli/run-script@10.0.0cb36a8a#8576init-package-json@8.2.2b6bb9ae#8576pacote@21.0.31b4433f#8576@npmcli/map-workspaces@5.0.0ceae674#8576@npmcli/package-json@7.0.14f37534#8576 remove read-package-json-fastChores
7eb5c09#8576 update package-lock with peer flag fixes (@wraithgar)0d00fd8#8576jsdom@27.0.0(@wraithgar)420a569#8576unified@11.0.5(@wraithgar)064deb3#8576remark-rehype@11.1.2(@wraithgar)30fe3ba#8576remark-man@9.0.0(@wraithgar)1c6bb4c#8576rehype-stringify@10.0.1(@wraithgar)208cb93#8576remark-gfm@4.0.1(@wraithgar)4a46b5a#8576remark-github@12.0.0(@wraithgar)93d190b#8576remark-parse@11.0.0(@wraithgar)05301a4#8576remark@15.0.1(@wraithgar)6afdda9#8576ajv-formats@3.0.1(@wraithgar)402a0ab#8576@npmcli/template-oss@4.25.1(@wraithgar)3b43bf7#8576 dev dependency updates (@wraithgar)9f9146f#8576@tufjs/repo-mock@4.0.0(@wraithgar)eed8a10#8576 use latest/local arborist in mock-registry (@wraithgar)@npmcli/arborist@9.1.5@npmcli/config@10.4.1libnpmaccess@10.0.2libnpmdiff@8.0.8libnpmexec@10.1.7libnpmfund@7.0.8libnpmorg@8.0.1libnpmpack@9.0.8libnpmpublish@11.1.1libnpmsearch@9.0.1libnpmteam@8.0.2libnpmversion@8.0.2v11.6.0Compare Source
Features
bdcc10d#8359 add support for optional env var replacements in .npmrc (#8359) (@aczekajski, @owlstronaut)Bug Fixes
dd4cee9#8539 powershell: improve argument parsing (#8539) (@alexsch01)5f18557#8532 powershell: fix issue with modified InvocationName (#8532) (@alexsch01)9e5abf1#8529 add redaction to log format egress (#8529) (@wraithgar)75ce64a#8524 revert handle signal exits gracefully (#8524) (@owlstronaut)5d82d0b#8469 ps1 scripts in powershell 5.1 (#8469) (@splatteredbits)Dependencies
@npmcli/arborist@9.1.4@npmcli/config@10.4.0libnpmdiff@8.0.7libnpmexec@10.1.6libnpmfund@7.0.7libnpmpack@9.0.7v11.5.2Compare Source
Bug Fixes
7d900c4#8467 oidc visibility check for provenance (#8467) (@reggi, @wraithgar)Documentation
d4e56b2#8459 update snapshot generation command (#8459) (@MikeMcC399)v11.5.1Compare Source
Bug Fixes
476bf17#8457 provenance should only default for oidc (@reggi)v11.5.0Compare Source
Features
1cce318#8336 adds support for oidc publish (#8336) (@reggi)Bug Fixes
7f66f0a#8447 add better hint forbeforeand clean up description (@wraithgar)280817a#8447 add --before param to command help output (@wraithgar)6e47325#8441 Makes 404 errors less scary without revealing existence (#8441) (@owlstronaut)0a97ffd#8429 handle signal exits gracefully (@owlstronaut)5b858c6#8411 ensure progress bars display consistently across all environments (#8411) (@owlstronaut)Documentation
ef3529e#8435 add test snapshot (#8435) (@reggi, @wraithgar)b7758d7#8418 remove reference to Node.js download less common os (#8418) (@MikeMcC399)746ac5d#8380 remove duplicate info (#8380) (@alexsch01)4673e9c#8371 rebrand OS X references to macOS (@MikeMcC399)Dependencies
398fed4#8450normalize-package-data@7.0.15b242c9#8450validate-npm-package-name@6.0.2d4e8a8a#8450tuf-js@3.1.0e1b37b2#8450picomatch@4.0.33cb5884#8450socks@2.8.6daea981#8450ci-info@4.3.039ad47d#8450aproba@2.1.0a789f33#8450agent-base@7.1.41c0d257#8450@npmcli/metavuln-calculator@9.0.1Chores
804a964#8450 update devDependencies in lockfile (@wraithgar)643ae71#8450 update mock-registry to use local arborist (@wraithgar)cf023d7#8421 contributing: prepare easier copy-paste contributing commands (#8421) (@MikeMcC399)3f60b5f#8383@npmcli/template-oss@4.24.4(#8383) (@wraithgar)01f8cc6#8381@npmcli/template-oss@4.24.3(#8381) (@wraithgar)@npmcli/arborist@9.1.3@npmcli/config@10.3.1libnpmdiff@8.0.6libnpmexec@10.1.5libnpmfund@7.0.6libnpmpack@9.0.6libnpmpublish@11.1.0v11.4.2Compare Source
Bug Fixes
d389614#8579 corrects peer dependency flag propagation (@owlstronaut)5db81c3#8512 allow concurrent non-local npx calls (#8512) (@jenseng, @wraithgar)Documentation
7a09902#8582 bring back certfile (#8582) (@jenseng)Dependencies
849dcb6#8589tar@7.5.1(#8589)ea15731#8576binary-extensions@3.1.00f41bac#8576tiny-relative-date@2.0.207bf540#8576is-cidr@6.0.0ef87ec6#8576diff@8.0.248285e0#8576 add fdir, isexe, and picomatch to node_modules099238a#8576fdir@6.5.06e4d673#8576isexe@3.1.109a7494#8576supports-color@10.2.2c5157c9#8576chalk@5.6.246035db#8576debug@4.4.35f6664b#8576spdx-license-ids@3.0.225516583#8576socks@2.8.76a392f3#8576tinyglobby@0.2.159519f18#8576npm-install-checks@7.1.234bafd1#8576node-gyp@11.4.2dfd034e#8576@npmcli/promise-spawn@8.0.3d4eef14#8576rimraf@6.0.1566f1b7#8576minimatch@10.0.3ac33497#8576mkdirp@3.0.11676626#8576glob@11.0.3817f0b1#8576ignore-walk@8.0.079a4e67#8576minizlib@3.0.238fa2c2#8576negotiator@1.0.024252a1#8576@npmcli/agent@4.0.0ea7ca5f#8576lru-cache@11.2.1521823b#8576@npmcli/git@7.0.0bf6b686#8576npm-package-arg@13.0.09392488#8576npm-package-manifest@11.0.10082083#8576normalize-package-data@8.0.0633c4ed#8576hosted-git-info@9.0.066f64eb#8576make-fetch-happen@15.0.21f85f94#8576@sigstore/tuf@4.0.0a2bdecc#8576sigstore@4.0.01149971#8576npm-registry-fetch@19.0.0b5bd5e3#8576npm-profile@12.0.06221e27#8576@npmcli/metavuln-calculator@9.0.2da81a37#8576cacache@20.0.16b4c5f9#8576@npmcli/run-script@10.0.0cb36a8a#8576init-package-json@8.2.2b6bb9ae#8576pacote@21.0.31b4433f#8576@npmcli/map-workspaces@5.0.0ceae674#8576@npmcli/package-json@7.0.14f37534#8576 remove read-package-json-fastChores
7eb5c09#8576 update package-lock with peer flag fixes (@wraithgar)0d00fd8#8576jsdom@27.0.0(@wraithgar)420a569#8576unified@11.0.5(@wraithgar)064deb3#8576remark-rehype@11.1.2(@wraithgar)30fe3ba#8576remark-man@9.0.0(@wraithgar)1c6bb4c#8576rehype-stringify@10.0.1(@wraithgar)208cb93#8576remark-gfm@4.0.1(@wraithgar)4a46b5a#8576remark-github@12.0.0(@wraithgar)93d190b#8576remark-parse@11.0.0(@wraithgar)05301a4#8576remark@15.0.1(@wraithgar)6afdda9#8576ajv-formats@3.0.1(@wraithgar)402a0ab#8576@npmcli/template-oss@4.25.1(@wraithgar)3b43bf7#8576 dev dependency updates (@wraithgar)9f9146f#8576@tufjs/repo-mock@4.0.0(@wraithgar)eed8a10#8576 use latest/local arborist in mock-registry (@wraithgar)@npmcli/arborist@9.1.5@npmcli/config@10.4.1libnpmaccess@10.0.2libnpmdiff@8.0.8libnpmexec@10.1.7libnpmfund@7.0.8libnpmorg@8.0.1libnpmpack@9.0.8libnpmpublish@11.1.1libnpmsearch@9.0.1libnpmteam@8.0.2libnpmversion@8.0.2v11.4.1Compare Source
Documentation
3ed764a#8308 Clarify script working directory behavior (fixes #8305) (#8308) (@tarekwfa0110, @owlstronaut)Chores
2f30251#8314 remove references to skimdb.npmjs.com (#8314) (@shmam)9cb9d50#8298 add contributor to changelog entry (#8298) (@wraithgar)Dependencies
@npmcli/arborist@9.1.1libnpmdiff@8.0.4libnpmexec@10.1.3libnpmfund@7.0.4libnpmpack@9.0.4v11.4.0Compare Source
Features
a0e60fb#8246 added init-private option (@owlstronaut)57aa89f#8265 use run by default and run-script as the alias (#8265) (@owlstronaut)0d4c023#8234 install: add package info to json output (#8234) (@wraithgar)Bug Fixes
8794fd9#8297 powershell: support pipeline input with Invoke-Expression (#8297) (@alexsch01)b5173d1#8293 docs: corrected github_path (#8293) (@xaos7991)2210d7a#8278 powershell: use Invoke-Expression to pass args (#8278) (@alexsch01, @mbtools)8669d09#8228 add otplease for enable-2fa, disable-2fa, access (#8228) (@reggi, @wraithgar)78b5a6f#8269 correctly handle scenario where prefix is the cwd (#8269) (@owlstronaut, @ficocelliguy)fdc3413#8221 exec: Fails to Execute Binaries Named After Shell Keywords (#8221) (@13sfaith)4b08e2e#8245 docs: prepare script runs for local package links (@milaninfy)1622ac4#8241 handle missingtimein packument to prevent crash onnpm view(@owlstronaut)db8f5da#8110 outdated: add dependent location in long output (#8110) (@milaninfy, @wraithgar)Documentation
d2498df[#8295](Configuration
📅 Schedule: Branch creation - "every weekday" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.