From 0c92c8bca10a7e6f58a5ca01b804274d594eb247 Mon Sep 17 00:00:00 2001
From: npm CLI robot
Date: Thu, 24 Sep 2026 18:28:22 +0000
Subject: [PATCH] deps: upgrade npm to 11.20.0
---
deps/npm/docs/content/commands/npm-ci.md | 2 +-
deps/npm/docs/content/commands/npm-exec.md | 2 +-
.../content/commands/npm-install-ci-test.md | 2 +-
.../docs/content/commands/npm-install-test.md | 2 +-
deps/npm/docs/content/commands/npm-install.md | 2 +-
deps/npm/docs/content/commands/npm-ls.md | 2 +-
deps/npm/docs/content/commands/npm-publish.md | 6 +
deps/npm/docs/content/commands/npm-rebuild.md | 2 +-
deps/npm/docs/content/commands/npm-stage.md | 2 +-
deps/npm/docs/content/commands/npm-token.md | 7 +-
deps/npm/docs/content/commands/npm-update.md | 2 +-
deps/npm/docs/content/commands/npm.md | 2 +-
deps/npm/docs/content/using-npm/config.md | 15 +-
deps/npm/docs/output/commands/npm-access.html | 4 +-
.../npm/docs/output/commands/npm-adduser.html | 4 +-
.../output/commands/npm-approve-scripts.html | 4 +-
deps/npm/docs/output/commands/npm-audit.html | 4 +-
deps/npm/docs/output/commands/npm-bugs.html | 4 +-
deps/npm/docs/output/commands/npm-cache.html | 4 +-
deps/npm/docs/output/commands/npm-ci.html | 5 +-
.../docs/output/commands/npm-completion.html | 4 +-
deps/npm/docs/output/commands/npm-config.html | 4 +-
deps/npm/docs/output/commands/npm-dedupe.html | 4 +-
.../output/commands/npm-deny-scripts.html | 4 +-
.../docs/output/commands/npm-deprecate.html | 4 +-
deps/npm/docs/output/commands/npm-diff.html | 4 +-
.../docs/output/commands/npm-dist-tag.html | 4 +-
deps/npm/docs/output/commands/npm-docs.html | 4 +-
deps/npm/docs/output/commands/npm-doctor.html | 4 +-
deps/npm/docs/output/commands/npm-edit.html | 4 +-
deps/npm/docs/output/commands/npm-exec.html | 5 +-
.../npm/docs/output/commands/npm-explain.html | 4 +-
.../npm/docs/output/commands/npm-explore.html | 4 +-
.../docs/output/commands/npm-find-dupes.html | 4 +-
deps/npm/docs/output/commands/npm-fund.html | 4 +-
deps/npm/docs/output/commands/npm-get.html | 4 +-
.../docs/output/commands/npm-help-search.html | 4 +-
deps/npm/docs/output/commands/npm-help.html | 4 +-
deps/npm/docs/output/commands/npm-init.html | 4 +-
.../output/commands/npm-install-ci-test.html | 5 +-
.../output/commands/npm-install-scripts.html | 4 +-
.../output/commands/npm-install-test.html | 5 +-
.../npm/docs/output/commands/npm-install.html | 5 +-
deps/npm/docs/output/commands/npm-link.html | 4 +-
deps/npm/docs/output/commands/npm-ll.html | 4 +-
deps/npm/docs/output/commands/npm-login.html | 4 +-
deps/npm/docs/output/commands/npm-logout.html | 4 +-
deps/npm/docs/output/commands/npm-ls.html | 6 +-
deps/npm/docs/output/commands/npm-org.html | 4 +-
.../docs/output/commands/npm-outdated.html | 4 +-
deps/npm/docs/output/commands/npm-owner.html | 4 +-
deps/npm/docs/output/commands/npm-pack.html | 4 +-
deps/npm/docs/output/commands/npm-ping.html | 4 +-
deps/npm/docs/output/commands/npm-pkg.html | 4 +-
deps/npm/docs/output/commands/npm-prefix.html | 4 +-
.../npm/docs/output/commands/npm-profile.html | 4 +-
deps/npm/docs/output/commands/npm-prune.html | 4 +-
.../npm/docs/output/commands/npm-publish.html | 8 +-
deps/npm/docs/output/commands/npm-query.html | 4 +-
.../npm/docs/output/commands/npm-rebuild.html | 5 +-
deps/npm/docs/output/commands/npm-repo.html | 4 +-
.../npm/docs/output/commands/npm-restart.html | 4 +-
deps/npm/docs/output/commands/npm-root.html | 4 +-
deps/npm/docs/output/commands/npm-run.html | 4 +-
deps/npm/docs/output/commands/npm-sbom.html | 4 +-
deps/npm/docs/output/commands/npm-search.html | 4 +-
deps/npm/docs/output/commands/npm-set.html | 4 +-
.../docs/output/commands/npm-shrinkwrap.html | 4 +-
deps/npm/docs/output/commands/npm-stage.html | 6 +-
deps/npm/docs/output/commands/npm-star.html | 4 +-
deps/npm/docs/output/commands/npm-stars.html | 4 +-
deps/npm/docs/output/commands/npm-start.html | 4 +-
deps/npm/docs/output/commands/npm-stop.html | 4 +-
deps/npm/docs/output/commands/npm-team.html | 4 +-
deps/npm/docs/output/commands/npm-test.html | 4 +-
deps/npm/docs/output/commands/npm-token.html | 11 +-
deps/npm/docs/output/commands/npm-trust.html | 4 +-
.../docs/output/commands/npm-undeprecate.html | 4 +-
.../docs/output/commands/npm-uninstall.html | 4 +-
.../docs/output/commands/npm-unpublish.html | 4 +-
deps/npm/docs/output/commands/npm-unstar.html | 4 +-
deps/npm/docs/output/commands/npm-update.html | 5 +-
.../npm/docs/output/commands/npm-version.html | 4 +-
deps/npm/docs/output/commands/npm-view.html | 4 +-
deps/npm/docs/output/commands/npm-whoami.html | 4 +-
deps/npm/docs/output/commands/npm.html | 6 +-
deps/npm/docs/output/commands/npx.html | 4 +-
.../docs/output/configuring-npm/folders.html | 4 +-
.../docs/output/configuring-npm/install.html | 4 +-
.../output/configuring-npm/npm-global.html | 4 +-
.../docs/output/configuring-npm/npm-json.html | 4 +-
.../configuring-npm/npm-shrinkwrap-json.html | 4 +-
.../docs/output/configuring-npm/npmrc.html | 4 +-
.../output/configuring-npm/package-json.html | 4 +-
.../configuring-npm/package-lock-json.html | 4 +-
deps/npm/docs/output/using-npm/config.html | 16 +-
.../using-npm/dependency-selectors.html | 4 +-
.../npm/docs/output/using-npm/developers.html | 4 +-
deps/npm/docs/output/using-npm/logging.html | 4 +-
deps/npm/docs/output/using-npm/orgs.html | 4 +-
.../docs/output/using-npm/package-spec.html | 4 +-
deps/npm/docs/output/using-npm/registry.html | 4 +-
deps/npm/docs/output/using-npm/removal.html | 4 +-
deps/npm/docs/output/using-npm/scope.html | 4 +-
deps/npm/docs/output/using-npm/scripts.html | 4 +-
.../npm/docs/output/using-npm/workspaces.html | 4 +-
deps/npm/lib/commands/token.js | 19 ++
deps/npm/lib/utils/allow-scripts-writer.js | 4 +-
deps/npm/lib/utils/key-values.js | 14 +-
deps/npm/lib/utils/oidc.js | 6 +-
deps/npm/lib/utils/reify-output.js | 5 +-
deps/npm/man/man1/npm-access.1 | 2 +-
deps/npm/man/man1/npm-adduser.1 | 2 +-
deps/npm/man/man1/npm-approve-scripts.1 | 2 +-
deps/npm/man/man1/npm-audit.1 | 2 +-
deps/npm/man/man1/npm-bugs.1 | 2 +-
deps/npm/man/man1/npm-cache.1 | 2 +-
deps/npm/man/man1/npm-ci.1 | 4 +-
deps/npm/man/man1/npm-completion.1 | 2 +-
deps/npm/man/man1/npm-config.1 | 2 +-
deps/npm/man/man1/npm-dedupe.1 | 2 +-
deps/npm/man/man1/npm-deny-scripts.1 | 2 +-
deps/npm/man/man1/npm-deprecate.1 | 2 +-
deps/npm/man/man1/npm-diff.1 | 2 +-
deps/npm/man/man1/npm-dist-tag.1 | 2 +-
deps/npm/man/man1/npm-docs.1 | 2 +-
deps/npm/man/man1/npm-doctor.1 | 2 +-
deps/npm/man/man1/npm-edit.1 | 2 +-
deps/npm/man/man1/npm-exec.1 | 4 +-
deps/npm/man/man1/npm-explain.1 | 2 +-
deps/npm/man/man1/npm-explore.1 | 2 +-
deps/npm/man/man1/npm-find-dupes.1 | 2 +-
deps/npm/man/man1/npm-fund.1 | 2 +-
deps/npm/man/man1/npm-get.1 | 2 +-
deps/npm/man/man1/npm-help-search.1 | 2 +-
deps/npm/man/man1/npm-help.1 | 2 +-
deps/npm/man/man1/npm-init.1 | 2 +-
deps/npm/man/man1/npm-install-ci-test.1 | 4 +-
deps/npm/man/man1/npm-install-scripts.1 | 2 +-
deps/npm/man/man1/npm-install-test.1 | 4 +-
deps/npm/man/man1/npm-install.1 | 4 +-
deps/npm/man/man1/npm-link.1 | 2 +-
deps/npm/man/man1/npm-ll.1 | 2 +-
deps/npm/man/man1/npm-login.1 | 2 +-
deps/npm/man/man1/npm-logout.1 | 2 +-
deps/npm/man/man1/npm-ls.1 | 4 +-
deps/npm/man/man1/npm-org.1 | 2 +-
deps/npm/man/man1/npm-outdated.1 | 2 +-
deps/npm/man/man1/npm-owner.1 | 2 +-
deps/npm/man/man1/npm-pack.1 | 2 +-
deps/npm/man/man1/npm-ping.1 | 2 +-
deps/npm/man/man1/npm-pkg.1 | 2 +-
deps/npm/man/man1/npm-prefix.1 | 2 +-
deps/npm/man/man1/npm-profile.1 | 2 +-
deps/npm/man/man1/npm-prune.1 | 2 +-
deps/npm/man/man1/npm-publish.1 | 6 +-
deps/npm/man/man1/npm-query.1 | 2 +-
deps/npm/man/man1/npm-rebuild.1 | 4 +-
deps/npm/man/man1/npm-repo.1 | 2 +-
deps/npm/man/man1/npm-restart.1 | 2 +-
deps/npm/man/man1/npm-root.1 | 2 +-
deps/npm/man/man1/npm-run.1 | 2 +-
deps/npm/man/man1/npm-sbom.1 | 2 +-
deps/npm/man/man1/npm-search.1 | 2 +-
deps/npm/man/man1/npm-set.1 | 2 +-
deps/npm/man/man1/npm-shrinkwrap.1 | 2 +-
deps/npm/man/man1/npm-stage.1 | 4 +-
deps/npm/man/man1/npm-star.1 | 2 +-
deps/npm/man/man1/npm-stars.1 | 2 +-
deps/npm/man/man1/npm-start.1 | 2 +-
deps/npm/man/man1/npm-stop.1 | 2 +-
deps/npm/man/man1/npm-team.1 | 2 +-
deps/npm/man/man1/npm-test.1 | 2 +-
deps/npm/man/man1/npm-token.1 | 6 +-
deps/npm/man/man1/npm-trust.1 | 2 +-
deps/npm/man/man1/npm-undeprecate.1 | 2 +-
deps/npm/man/man1/npm-uninstall.1 | 2 +-
deps/npm/man/man1/npm-unpublish.1 | 2 +-
deps/npm/man/man1/npm-unstar.1 | 2 +-
deps/npm/man/man1/npm-update.1 | 4 +-
deps/npm/man/man1/npm-version.1 | 2 +-
deps/npm/man/man1/npm-view.1 | 2 +-
deps/npm/man/man1/npm-whoami.1 | 2 +-
deps/npm/man/man1/npm.1 | 4 +-
deps/npm/man/man1/npx.1 | 2 +-
deps/npm/man/man5/folders.5 | 2 +-
deps/npm/man/man5/install.5 | 2 +-
deps/npm/man/man5/npm-global.5 | 2 +-
deps/npm/man/man5/npm-json.5 | 2 +-
deps/npm/man/man5/npm-shrinkwrap-json.5 | 2 +-
deps/npm/man/man5/npmrc.5 | 2 +-
deps/npm/man/man5/package-json.5 | 2 +-
deps/npm/man/man5/package-lock-json.5 | 2 +-
deps/npm/man/man7/config.7 | 12 +-
deps/npm/man/man7/dependency-selectors.7 | 2 +-
deps/npm/man/man7/developers.7 | 2 +-
deps/npm/man/man7/logging.7 | 2 +-
deps/npm/man/man7/orgs.7 | 2 +-
deps/npm/man/man7/package-spec.7 | 2 +-
deps/npm/man/man7/registry.7 | 2 +-
deps/npm/man/man7/removal.7 | 2 +-
deps/npm/man/man7/scope.7 | 2 +-
deps/npm/man/man7/scripts.7 | 2 +-
deps/npm/man/man7/workspaces.7 | 2 +-
.../arborist/lib/arborist/build-ideal-tree.js | 26 ++
.../@npmcli/arborist/lib/script-allowed.js | 12 +-
.../@npmcli/arborist/package.json | 2 +-
.../config/lib/definitions/definitions.js | 14 +-
.../node_modules/@npmcli/config/package.json | 2 +-
deps/npm/node_modules/libnpmdiff/package.json | 4 +-
deps/npm/node_modules/libnpmexec/package.json | 4 +-
deps/npm/node_modules/libnpmfund/package.json | 4 +-
deps/npm/node_modules/libnpmpack/package.json | 4 +-
deps/npm/node_modules/libnpmpublish/README.md | 8 +-
.../node_modules/libnpmpublish/lib/publish.js | 6 +
.../node_modules/libnpmpublish/package.json | 2 +-
deps/npm/package.json | 16 +-
.../tap-snapshots/test/lib/docs.js.test.cjs | 17 +-
deps/npm/test/fixtures/mock-oidc.js | 7 +-
deps/npm/test/lib/commands/pack.js | 10 +-
deps/npm/test/lib/commands/publish.js | 252 ++++++++++++++++++
deps/npm/test/lib/commands/stage/list.js | 7 +
deps/npm/test/lib/commands/stage/view.js | 3 +
deps/npm/test/lib/commands/token.js | 112 ++++++++
deps/npm/test/lib/commands/uninstall.js | 28 ++
.../npm/test/lib/utils/allow-scripts-prune.js | 21 ++
.../test/lib/utils/allow-scripts-writer.js | 41 +++
deps/npm/test/lib/utils/key-values.js | 34 +++
deps/npm/test/lib/utils/reify-output.js | 76 ++++++
.../test/lib/utils/resolve-allow-scripts.js | 16 ++
230 files changed, 1105 insertions(+), 351 deletions(-)
diff --git a/deps/npm/docs/content/commands/npm-ci.md b/deps/npm/docs/content/commands/npm-ci.md
index 741caf5eae7..8cf6a42690b 100644
--- a/deps/npm/docs/content/commands/npm-ci.md
+++ b/deps/npm/docs/content/commands/npm-ci.md
@@ -290,7 +290,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-exec.md b/deps/npm/docs/content/commands/npm-exec.md
index ff08d07786a..87be6dbfd67 100644
--- a/deps/npm/docs/content/commands/npm-exec.md
+++ b/deps/npm/docs/content/commands/npm-exec.md
@@ -178,7 +178,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-install-ci-test.md b/deps/npm/docs/content/commands/npm-install-ci-test.md
index 2194a4df84a..66774863573 100644
--- a/deps/npm/docs/content/commands/npm-install-ci-test.md
+++ b/deps/npm/docs/content/commands/npm-install-ci-test.md
@@ -243,7 +243,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-install-test.md b/deps/npm/docs/content/commands/npm-install-test.md
index e13f79a51e6..4311f80279d 100644
--- a/deps/npm/docs/content/commands/npm-install-test.md
+++ b/deps/npm/docs/content/commands/npm-install-test.md
@@ -320,7 +320,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-install.md b/deps/npm/docs/content/commands/npm-install.md
index 98d69d5e842..efc07bc7598 100644
--- a/deps/npm/docs/content/commands/npm-install.md
+++ b/deps/npm/docs/content/commands/npm-install.md
@@ -662,7 +662,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-ls.md b/deps/npm/docs/content/commands/npm-ls.md
index b38603c203f..e3be39fcf04 100644
--- a/deps/npm/docs/content/commands/npm-ls.md
+++ b/deps/npm/docs/content/commands/npm-ls.md
@@ -23,7 +23,7 @@ Note that nested packages will *also* show the paths to the specified packages.
For example, running `npm ls promzard` in npm's source tree will show:
```bash
-npm@11.19.1 /path/to/npm
+npm@11.20.0 /path/to/npm
└─┬ init-package-json@0.0.4
└── promzard@0.1.5
```
diff --git a/deps/npm/docs/content/commands/npm-publish.md b/deps/npm/docs/content/commands/npm-publish.md
index 04c020b3563..f0999657fc0 100644
--- a/deps/npm/docs/content/commands/npm-publish.md
+++ b/deps/npm/docs/content/commands/npm-publish.md
@@ -222,6 +222,9 @@ This value is not exported to the environment for child processes.
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the `provenance-file` config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
+
This config cannot be used with: `provenance-file`
#### `provenance-file`
@@ -231,6 +234,9 @@ This config cannot be used with: `provenance-file`
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
+
This config cannot be used with: `provenance`
### See Also
diff --git a/deps/npm/docs/content/commands/npm-rebuild.md b/deps/npm/docs/content/commands/npm-rebuild.md
index c70307a2a7f..6b3095ff9d1 100644
--- a/deps/npm/docs/content/commands/npm-rebuild.md
+++ b/deps/npm/docs/content/commands/npm-rebuild.md
@@ -120,7 +120,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm-stage.md b/deps/npm/docs/content/commands/npm-stage.md
index 798d6c2d953..4228a43cce7 100644
--- a/deps/npm/docs/content/commands/npm-stage.md
+++ b/deps/npm/docs/content/commands/npm-stage.md
@@ -158,7 +158,7 @@ npm stage publish
| `--workspace`, `-w` | | String (can be set multiple times) | Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the `workspace` config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the `npm init` command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. |
| `--workspaces` | null | null or Boolean | Set to true to run the command in the context of **all** configured workspaces. Explicitly setting this to false will cause commands like `install` to ignore workspaces altogether. When not set explicitly: - Commands that operate on the `node_modules` tree (install, update, etc.) will link workspaces into the `node_modules` folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, _unless_ one or more workspaces are specified in the `workspace` config. |
| `--include-workspace-root` | false | Boolean | Include the workspace root when workspaces are enabled for a command. When false, specifying individual workspaces via the `workspace` config, or all workspaces via the `workspaces` flag, will cause npm to operate only on the specified workspaces, and not on the root project. |
-| `--provenance` | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. |
+| `--provenance` | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. When the `provenance-file` config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped. |
### `npm stage list`
diff --git a/deps/npm/docs/content/commands/npm-token.md b/deps/npm/docs/content/commands/npm-token.md
index 3c8e08d7fc3..45e9347f9d0 100644
--- a/deps/npm/docs/content/commands/npm-token.md
+++ b/deps/npm/docs/content/commands/npm-token.md
@@ -110,11 +110,14 @@ the token access to specific organizations.
#### `packages-and-scopes-permission`
* Default: null
-* Type: null, "read-only", "read-write", or "no-access"
+* Type: null, "read-only", "read-write", "read-write-stage-only", or
+ "no-access"
When creating a Granular Access Token with `npm token create`, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
diff --git a/deps/npm/docs/content/commands/npm-update.md b/deps/npm/docs/content/commands/npm-update.md
index 317f85f7d0d..6da8ef5ac0e 100644
--- a/deps/npm/docs/content/commands/npm-update.md
+++ b/deps/npm/docs/content/commands/npm-update.md
@@ -330,7 +330,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `strict-allow-scripts`
diff --git a/deps/npm/docs/content/commands/npm.md b/deps/npm/docs/content/commands/npm.md
index 75157bd7b59..7789159b987 100644
--- a/deps/npm/docs/content/commands/npm.md
+++ b/deps/npm/docs/content/commands/npm.md
@@ -14,7 +14,7 @@ Note: This command is unaware of workspaces.
### Version
-11.19.1
+11.20.0
### Description
diff --git a/deps/npm/docs/content/using-npm/config.md b/deps/npm/docs/content/using-npm/config.md
index 5d951493e8a..71743e7fea3 100644
--- a/deps/npm/docs/content/using-npm/config.md
+++ b/deps/npm/docs/content/using-npm/config.md
@@ -271,7 +271,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. `--ignore-scripts` and
`--dangerously-allow-all-scripts` both override this setting.
-
+This value is not exported to the environment for child processes.
#### `allow-scripts-pending`
@@ -1473,11 +1473,14 @@ token access to all packages instead of limiting to specific packages.
#### `packages-and-scopes-permission`
* Default: null
-* Type: null, "read-only", "read-write", or "no-access"
+* Type: null, "read-only", "read-write", "read-write-stage-only", or
+ "no-access"
When creating a Granular Access Token with `npm token create`, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
@@ -1575,6 +1578,9 @@ Set to `false` to suppress the progress bar.
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the `provenance-file` config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
+
This config cannot be used with: `provenance-file`
#### `provenance-file`
@@ -1584,6 +1590,9 @@ This config cannot be used with: `provenance-file`
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
+
This config cannot be used with: `provenance`
#### `proxy`
diff --git a/deps/npm/docs/output/commands/npm-access.html b/deps/npm/docs/output/commands/npm-access.html
index ac6df64b960..9e232c895e9 100644
--- a/deps/npm/docs/output/commands/npm-access.html
+++ b/deps/npm/docs/output/commands/npm-access.html
@@ -186,9 +186,9 @@
-
+
npm-access
- @11.19.1
+ @11.20.0
Set access level on published packages
diff --git a/deps/npm/docs/output/commands/npm-adduser.html b/deps/npm/docs/output/commands/npm-adduser.html
index 29aec6314e9..f1fdd66f309 100644
--- a/deps/npm/docs/output/commands/npm-adduser.html
+++ b/deps/npm/docs/output/commands/npm-adduser.html
@@ -186,9 +186,9 @@
-
+
npm-adduser
- @11.19.1
+ @11.20.0
Add a registry user account
diff --git a/deps/npm/docs/output/commands/npm-approve-scripts.html b/deps/npm/docs/output/commands/npm-approve-scripts.html
index 3d61cc8ea23..8b54f89168b 100644
--- a/deps/npm/docs/output/commands/npm-approve-scripts.html
+++ b/deps/npm/docs/output/commands/npm-approve-scripts.html
@@ -186,9 +186,9 @@
-
+
npm-approve-scripts
- @11.19.1
+ @11.20.0
Approve install scripts for specific dependencies
diff --git a/deps/npm/docs/output/commands/npm-audit.html b/deps/npm/docs/output/commands/npm-audit.html
index 9117faa9bed..d093dc1d253 100644
--- a/deps/npm/docs/output/commands/npm-audit.html
+++ b/deps/npm/docs/output/commands/npm-audit.html
@@ -186,9 +186,9 @@
-
+
npm-audit
- @11.19.1
+ @11.20.0
Run a security audit
diff --git a/deps/npm/docs/output/commands/npm-bugs.html b/deps/npm/docs/output/commands/npm-bugs.html
index 63f4c29210a..98cc06a6698 100644
--- a/deps/npm/docs/output/commands/npm-bugs.html
+++ b/deps/npm/docs/output/commands/npm-bugs.html
@@ -186,9 +186,9 @@
-
+
npm-bugs
- @11.19.1
+ @11.20.0
Report bugs for a package in a web browser
diff --git a/deps/npm/docs/output/commands/npm-cache.html b/deps/npm/docs/output/commands/npm-cache.html
index 3377b00cc56..9f49c537846 100644
--- a/deps/npm/docs/output/commands/npm-cache.html
+++ b/deps/npm/docs/output/commands/npm-cache.html
@@ -186,9 +186,9 @@
-
+
npm-cache
- @11.19.1
+ @11.20.0
Manipulates packages cache
diff --git a/deps/npm/docs/output/commands/npm-ci.html b/deps/npm/docs/output/commands/npm-ci.html
index edde5bbdef6..5ef13e2947b 100644
--- a/deps/npm/docs/output/commands/npm-ci.html
+++ b/deps/npm/docs/output/commands/npm-ci.html
@@ -186,9 +186,9 @@
-
+
npm-ci
- @11.19.1
+ @11.20.0
Clean install a project
@@ -414,6 +414,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-completion.html b/deps/npm/docs/output/commands/npm-completion.html
index b5a6f445d45..69e1b5771a2 100644
--- a/deps/npm/docs/output/commands/npm-completion.html
+++ b/deps/npm/docs/output/commands/npm-completion.html
@@ -186,9 +186,9 @@
-
+
npm-completion
- @11.19.1
+ @11.20.0
Tab Completion for npm
diff --git a/deps/npm/docs/output/commands/npm-config.html b/deps/npm/docs/output/commands/npm-config.html
index c9ea9080cf7..bb6a7770b93 100644
--- a/deps/npm/docs/output/commands/npm-config.html
+++ b/deps/npm/docs/output/commands/npm-config.html
@@ -186,9 +186,9 @@
-
+
npm-config
- @11.19.1
+ @11.20.0
Manage the npm configuration files
diff --git a/deps/npm/docs/output/commands/npm-dedupe.html b/deps/npm/docs/output/commands/npm-dedupe.html
index abe4a229e77..8437b66e533 100644
--- a/deps/npm/docs/output/commands/npm-dedupe.html
+++ b/deps/npm/docs/output/commands/npm-dedupe.html
@@ -186,9 +186,9 @@
-
+
npm-dedupe
- @11.19.1
+ @11.20.0
Reduce duplication in the package tree
diff --git a/deps/npm/docs/output/commands/npm-deny-scripts.html b/deps/npm/docs/output/commands/npm-deny-scripts.html
index 3a56f32dc97..53789799855 100644
--- a/deps/npm/docs/output/commands/npm-deny-scripts.html
+++ b/deps/npm/docs/output/commands/npm-deny-scripts.html
@@ -186,9 +186,9 @@
-
+
npm-deny-scripts
- @11.19.1
+ @11.20.0
Deny install scripts for specific dependencies
diff --git a/deps/npm/docs/output/commands/npm-deprecate.html b/deps/npm/docs/output/commands/npm-deprecate.html
index 90f45466cad..bbd8d76fac0 100644
--- a/deps/npm/docs/output/commands/npm-deprecate.html
+++ b/deps/npm/docs/output/commands/npm-deprecate.html
@@ -186,9 +186,9 @@
-
+
npm-deprecate
- @11.19.1
+ @11.20.0
Deprecate a version of a package
diff --git a/deps/npm/docs/output/commands/npm-diff.html b/deps/npm/docs/output/commands/npm-diff.html
index fba245e3b33..0a23ac8cf7b 100644
--- a/deps/npm/docs/output/commands/npm-diff.html
+++ b/deps/npm/docs/output/commands/npm-diff.html
@@ -186,9 +186,9 @@
-
+
npm-diff
- @11.19.1
+ @11.20.0
The registry diff command
diff --git a/deps/npm/docs/output/commands/npm-dist-tag.html b/deps/npm/docs/output/commands/npm-dist-tag.html
index 2d42ee8e3e8..b5d56fa965f 100644
--- a/deps/npm/docs/output/commands/npm-dist-tag.html
+++ b/deps/npm/docs/output/commands/npm-dist-tag.html
@@ -186,9 +186,9 @@
-
+
npm-dist-tag
- @11.19.1
+ @11.20.0
Modify package distribution tags
diff --git a/deps/npm/docs/output/commands/npm-docs.html b/deps/npm/docs/output/commands/npm-docs.html
index 98295c7943e..ee20bd23abd 100644
--- a/deps/npm/docs/output/commands/npm-docs.html
+++ b/deps/npm/docs/output/commands/npm-docs.html
@@ -186,9 +186,9 @@
-
+
npm-docs
- @11.19.1
+ @11.20.0
Open documentation for a package in a web browser
diff --git a/deps/npm/docs/output/commands/npm-doctor.html b/deps/npm/docs/output/commands/npm-doctor.html
index 096f12bf3b8..c7a3368b35c 100644
--- a/deps/npm/docs/output/commands/npm-doctor.html
+++ b/deps/npm/docs/output/commands/npm-doctor.html
@@ -186,9 +186,9 @@
-
+
npm-doctor
- @11.19.1
+ @11.20.0
Check the health of your npm environment
diff --git a/deps/npm/docs/output/commands/npm-edit.html b/deps/npm/docs/output/commands/npm-edit.html
index 7a555a8f39a..ab465f52017 100644
--- a/deps/npm/docs/output/commands/npm-edit.html
+++ b/deps/npm/docs/output/commands/npm-edit.html
@@ -186,9 +186,9 @@
-
+
npm-edit
- @11.19.1
+ @11.20.0
Edit an installed package
diff --git a/deps/npm/docs/output/commands/npm-exec.html b/deps/npm/docs/output/commands/npm-exec.html
index 94e8e68c05f..67b114949b7 100644
--- a/deps/npm/docs/output/commands/npm-exec.html
+++ b/deps/npm/docs/output/commands/npm-exec.html
@@ -186,9 +186,9 @@
-
+
npm-exec
- @11.19.1
+ @11.20.0
Run a command from a local or remote npm package
@@ -324,6 +324,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-explain.html b/deps/npm/docs/output/commands/npm-explain.html
index ccf68b22712..3cc89e27ceb 100644
--- a/deps/npm/docs/output/commands/npm-explain.html
+++ b/deps/npm/docs/output/commands/npm-explain.html
@@ -186,9 +186,9 @@
-
+
npm-explain
- @11.19.1
+ @11.20.0
Explain installed packages
diff --git a/deps/npm/docs/output/commands/npm-explore.html b/deps/npm/docs/output/commands/npm-explore.html
index 7b4d6a2ed2c..028b6ba5ba8 100644
--- a/deps/npm/docs/output/commands/npm-explore.html
+++ b/deps/npm/docs/output/commands/npm-explore.html
@@ -186,9 +186,9 @@
-
+
npm-explore
- @11.19.1
+ @11.20.0
Browse an installed package
diff --git a/deps/npm/docs/output/commands/npm-find-dupes.html b/deps/npm/docs/output/commands/npm-find-dupes.html
index 19b5ae4ffcf..3476968389e 100644
--- a/deps/npm/docs/output/commands/npm-find-dupes.html
+++ b/deps/npm/docs/output/commands/npm-find-dupes.html
@@ -186,9 +186,9 @@
-
+
npm-find-dupes
- @11.19.1
+ @11.20.0
Find duplication in the package tree
diff --git a/deps/npm/docs/output/commands/npm-fund.html b/deps/npm/docs/output/commands/npm-fund.html
index c657d182afd..181e029e6c1 100644
--- a/deps/npm/docs/output/commands/npm-fund.html
+++ b/deps/npm/docs/output/commands/npm-fund.html
@@ -186,9 +186,9 @@
-
+
npm-fund
- @11.19.1
+ @11.20.0
Retrieve funding information
diff --git a/deps/npm/docs/output/commands/npm-get.html b/deps/npm/docs/output/commands/npm-get.html
index 59eaf5e577c..02feaf3e737 100644
--- a/deps/npm/docs/output/commands/npm-get.html
+++ b/deps/npm/docs/output/commands/npm-get.html
@@ -186,9 +186,9 @@
-
+
npm-get
- @11.19.1
+ @11.20.0
Get a value from the npm configuration
diff --git a/deps/npm/docs/output/commands/npm-help-search.html b/deps/npm/docs/output/commands/npm-help-search.html
index d4abfb29c36..b32d1585994 100644
--- a/deps/npm/docs/output/commands/npm-help-search.html
+++ b/deps/npm/docs/output/commands/npm-help-search.html
@@ -186,9 +186,9 @@
-
+
npm-help-search
- @11.19.1
+ @11.20.0
Search npm help documentation
diff --git a/deps/npm/docs/output/commands/npm-help.html b/deps/npm/docs/output/commands/npm-help.html
index d4fe535e8bd..4e0a516a694 100644
--- a/deps/npm/docs/output/commands/npm-help.html
+++ b/deps/npm/docs/output/commands/npm-help.html
@@ -186,9 +186,9 @@
-
+
npm-help
- @11.19.1
+ @11.20.0
Get help on npm
diff --git a/deps/npm/docs/output/commands/npm-init.html b/deps/npm/docs/output/commands/npm-init.html
index af686f90a7a..b0fefd70408 100644
--- a/deps/npm/docs/output/commands/npm-init.html
+++ b/deps/npm/docs/output/commands/npm-init.html
@@ -186,9 +186,9 @@
-
+
npm-init
- @11.19.1
+ @11.20.0
Create a package.json file
diff --git a/deps/npm/docs/output/commands/npm-install-ci-test.html b/deps/npm/docs/output/commands/npm-install-ci-test.html
index bdf779e2eef..1c62ffb640b 100644
--- a/deps/npm/docs/output/commands/npm-install-ci-test.html
+++ b/deps/npm/docs/output/commands/npm-install-ci-test.html
@@ -186,9 +186,9 @@
-
+
npm-install-ci-test
- @11.19.1
+ @11.20.0
Install a project with a clean slate and run tests
@@ -378,6 +378,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-install-scripts.html b/deps/npm/docs/output/commands/npm-install-scripts.html
index 8174e90a509..746b9bcbb9c 100644
--- a/deps/npm/docs/output/commands/npm-install-scripts.html
+++ b/deps/npm/docs/output/commands/npm-install-scripts.html
@@ -186,9 +186,9 @@
-
+
npm-install-scripts
- @11.19.1
+ @11.20.0
Manage install-script approvals for dependencies
diff --git a/deps/npm/docs/output/commands/npm-install-test.html b/deps/npm/docs/output/commands/npm-install-test.html
index e75fb52d323..17542aae9e7 100644
--- a/deps/npm/docs/output/commands/npm-install-test.html
+++ b/deps/npm/docs/output/commands/npm-install-test.html
@@ -186,9 +186,9 @@
-
+
npm-install-test
- @11.19.1
+ @11.20.0
Install package(s) and run tests
@@ -434,6 +434,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-install.html b/deps/npm/docs/output/commands/npm-install.html
index ed78f6576bb..47ac2f05628 100644
--- a/deps/npm/docs/output/commands/npm-install.html
+++ b/deps/npm/docs/output/commands/npm-install.html
@@ -186,9 +186,9 @@
-
+
npm-install
- @11.19.1
+ @11.20.0
Install a package
@@ -709,6 +709,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-link.html b/deps/npm/docs/output/commands/npm-link.html
index aa01ff7a259..bb707c9d73b 100644
--- a/deps/npm/docs/output/commands/npm-link.html
+++ b/deps/npm/docs/output/commands/npm-link.html
@@ -186,9 +186,9 @@
-
+
npm-link
- @11.19.1
+ @11.20.0
Symlink a package folder
diff --git a/deps/npm/docs/output/commands/npm-ll.html b/deps/npm/docs/output/commands/npm-ll.html
index f8df2515bfa..c54f5a6e41e 100644
--- a/deps/npm/docs/output/commands/npm-ll.html
+++ b/deps/npm/docs/output/commands/npm-ll.html
@@ -186,9 +186,9 @@
-
+
npm-ll
- @11.19.1
+ @11.20.0
List installed packages
diff --git a/deps/npm/docs/output/commands/npm-login.html b/deps/npm/docs/output/commands/npm-login.html
index 1c6d938ec6c..16703d1ce17 100644
--- a/deps/npm/docs/output/commands/npm-login.html
+++ b/deps/npm/docs/output/commands/npm-login.html
@@ -186,9 +186,9 @@
-
+
npm-login
- @11.19.1
+ @11.20.0
Login to a registry user account
diff --git a/deps/npm/docs/output/commands/npm-logout.html b/deps/npm/docs/output/commands/npm-logout.html
index cf319a086f8..f5712b45634 100644
--- a/deps/npm/docs/output/commands/npm-logout.html
+++ b/deps/npm/docs/output/commands/npm-logout.html
@@ -186,9 +186,9 @@
-
+
npm-logout
- @11.19.1
+ @11.20.0
Log out of the registry
diff --git a/deps/npm/docs/output/commands/npm-ls.html b/deps/npm/docs/output/commands/npm-ls.html
index b733762be37..e09112e22d8 100644
--- a/deps/npm/docs/output/commands/npm-ls.html
+++ b/deps/npm/docs/output/commands/npm-ls.html
@@ -186,9 +186,9 @@
-
+
npm-ls
- @11.19.1
+ @11.20.0
List installed packages
@@ -209,7 +209,7 @@ Description
Positional arguments are name@version-range identifiers, which will limit the results to only the paths to the packages named.
Note that nested packages will also show the paths to the specified packages.
For example, running npm ls promzard in npm's source tree will show:
-npm@11.19.1 /path/to/npm
+npm@11.20.0 /path/to/npm
└─┬ init-package-json@0.0.4
└── promzard@0.1.5
diff --git a/deps/npm/docs/output/commands/npm-org.html b/deps/npm/docs/output/commands/npm-org.html
index 6a2c22951a6..7618c07e555 100644
--- a/deps/npm/docs/output/commands/npm-org.html
+++ b/deps/npm/docs/output/commands/npm-org.html
@@ -186,9 +186,9 @@
-
+
npm-org
- @11.19.1
+ @11.20.0
Manage orgs
diff --git a/deps/npm/docs/output/commands/npm-outdated.html b/deps/npm/docs/output/commands/npm-outdated.html
index b85880371cd..b4a7eaf7223 100644
--- a/deps/npm/docs/output/commands/npm-outdated.html
+++ b/deps/npm/docs/output/commands/npm-outdated.html
@@ -186,9 +186,9 @@
-
+
npm-outdated
- @11.19.1
+ @11.20.0
Check for outdated packages
diff --git a/deps/npm/docs/output/commands/npm-owner.html b/deps/npm/docs/output/commands/npm-owner.html
index 6b8afff7ba3..83a0cabfe39 100644
--- a/deps/npm/docs/output/commands/npm-owner.html
+++ b/deps/npm/docs/output/commands/npm-owner.html
@@ -186,9 +186,9 @@
-
+
npm-owner
- @11.19.1
+ @11.20.0
Manage package owners
diff --git a/deps/npm/docs/output/commands/npm-pack.html b/deps/npm/docs/output/commands/npm-pack.html
index d7f148d92ed..9acd4c9d20e 100644
--- a/deps/npm/docs/output/commands/npm-pack.html
+++ b/deps/npm/docs/output/commands/npm-pack.html
@@ -186,9 +186,9 @@
-
+
npm-pack
- @11.19.1
+ @11.20.0
Create a tarball from a package
diff --git a/deps/npm/docs/output/commands/npm-ping.html b/deps/npm/docs/output/commands/npm-ping.html
index 3c49a071316..72779cc4512 100644
--- a/deps/npm/docs/output/commands/npm-ping.html
+++ b/deps/npm/docs/output/commands/npm-ping.html
@@ -186,9 +186,9 @@
-
+
npm-ping
- @11.19.1
+ @11.20.0
Ping npm registry
diff --git a/deps/npm/docs/output/commands/npm-pkg.html b/deps/npm/docs/output/commands/npm-pkg.html
index d80ac21f9af..7ae9d0b42fb 100644
--- a/deps/npm/docs/output/commands/npm-pkg.html
+++ b/deps/npm/docs/output/commands/npm-pkg.html
@@ -186,9 +186,9 @@
-
+
npm-pkg
- @11.19.1
+ @11.20.0
Manages your package.json
diff --git a/deps/npm/docs/output/commands/npm-prefix.html b/deps/npm/docs/output/commands/npm-prefix.html
index 1592a1d3048..b0043c87e35 100644
--- a/deps/npm/docs/output/commands/npm-prefix.html
+++ b/deps/npm/docs/output/commands/npm-prefix.html
@@ -186,9 +186,9 @@
-
+
npm-prefix
- @11.19.1
+ @11.20.0
Display prefix
diff --git a/deps/npm/docs/output/commands/npm-profile.html b/deps/npm/docs/output/commands/npm-profile.html
index 24f5db6d7f3..1183e9ef1f2 100644
--- a/deps/npm/docs/output/commands/npm-profile.html
+++ b/deps/npm/docs/output/commands/npm-profile.html
@@ -186,9 +186,9 @@
-
+
npm-profile
- @11.19.1
+ @11.20.0
Change settings on your registry profile
diff --git a/deps/npm/docs/output/commands/npm-prune.html b/deps/npm/docs/output/commands/npm-prune.html
index 736620c0a24..97728f904ef 100644
--- a/deps/npm/docs/output/commands/npm-prune.html
+++ b/deps/npm/docs/output/commands/npm-prune.html
@@ -186,9 +186,9 @@
-
+
npm-prune
- @11.19.1
+ @11.20.0
Remove extraneous packages
diff --git a/deps/npm/docs/output/commands/npm-publish.html b/deps/npm/docs/output/commands/npm-publish.html
index a20d56b8d10..60a816323cd 100644
--- a/deps/npm/docs/output/commands/npm-publish.html
+++ b/deps/npm/docs/output/commands/npm-publish.html
@@ -186,9 +186,9 @@
-
+
npm-publish
- @11.19.1
+ @11.20.0
Publish a package
@@ -360,6 +360,8 @@ provenance
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the provenance-file config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
This config cannot be used with: provenance-file
provenance-file
@@ -367,6 +369,8 @@ provenance-file
- Type: Path
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
This config cannot be used with: provenance
See Also
diff --git a/deps/npm/docs/output/commands/npm-query.html b/deps/npm/docs/output/commands/npm-query.html
index a74342cf278..0211cd7a25e 100644
--- a/deps/npm/docs/output/commands/npm-query.html
+++ b/deps/npm/docs/output/commands/npm-query.html
@@ -186,9 +186,9 @@
-
+
npm-query
- @11.19.1
+ @11.20.0
Dependency selector query
diff --git a/deps/npm/docs/output/commands/npm-rebuild.html b/deps/npm/docs/output/commands/npm-rebuild.html
index 39403a70941..f25623251ff 100644
--- a/deps/npm/docs/output/commands/npm-rebuild.html
+++ b/deps/npm/docs/output/commands/npm-rebuild.html
@@ -186,9 +186,9 @@
-
+
npm-rebuild
- @11.19.1
+ @11.20.0
Rebuild a package
@@ -286,6 +286,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-repo.html b/deps/npm/docs/output/commands/npm-repo.html
index 5337679c824..943c5177cbf 100644
--- a/deps/npm/docs/output/commands/npm-repo.html
+++ b/deps/npm/docs/output/commands/npm-repo.html
@@ -186,9 +186,9 @@
-
+
npm-repo
- @11.19.1
+ @11.20.0
Open package repository page in the browser
diff --git a/deps/npm/docs/output/commands/npm-restart.html b/deps/npm/docs/output/commands/npm-restart.html
index 0786bdc34a5..fce2e5b294e 100644
--- a/deps/npm/docs/output/commands/npm-restart.html
+++ b/deps/npm/docs/output/commands/npm-restart.html
@@ -186,9 +186,9 @@
-
+
npm-restart
- @11.19.1
+ @11.20.0
Restart a package
diff --git a/deps/npm/docs/output/commands/npm-root.html b/deps/npm/docs/output/commands/npm-root.html
index 165223c6fdb..88acaa9e893 100644
--- a/deps/npm/docs/output/commands/npm-root.html
+++ b/deps/npm/docs/output/commands/npm-root.html
@@ -186,9 +186,9 @@
-
+
npm-root
- @11.19.1
+ @11.20.0
Display npm root
diff --git a/deps/npm/docs/output/commands/npm-run.html b/deps/npm/docs/output/commands/npm-run.html
index 15ca998eb8a..ae867e8897f 100644
--- a/deps/npm/docs/output/commands/npm-run.html
+++ b/deps/npm/docs/output/commands/npm-run.html
@@ -186,9 +186,9 @@
-
+
npm-run
- @11.19.1
+ @11.20.0
Run arbitrary package scripts
diff --git a/deps/npm/docs/output/commands/npm-sbom.html b/deps/npm/docs/output/commands/npm-sbom.html
index fe84c36327a..ec88592fa2d 100644
--- a/deps/npm/docs/output/commands/npm-sbom.html
+++ b/deps/npm/docs/output/commands/npm-sbom.html
@@ -186,9 +186,9 @@
-
+
npm-sbom
- @11.19.1
+ @11.20.0
Generate a Software Bill of Materials (SBOM)
diff --git a/deps/npm/docs/output/commands/npm-search.html b/deps/npm/docs/output/commands/npm-search.html
index 98006e7d225..57b07bf1be8 100644
--- a/deps/npm/docs/output/commands/npm-search.html
+++ b/deps/npm/docs/output/commands/npm-search.html
@@ -186,9 +186,9 @@
-
+
npm-search
- @11.19.1
+ @11.20.0
Search for packages
diff --git a/deps/npm/docs/output/commands/npm-set.html b/deps/npm/docs/output/commands/npm-set.html
index 6202cdf7b3c..8ae84be0249 100644
--- a/deps/npm/docs/output/commands/npm-set.html
+++ b/deps/npm/docs/output/commands/npm-set.html
@@ -186,9 +186,9 @@
-
+
npm-set
- @11.19.1
+ @11.20.0
Set a value in the npm configuration
diff --git a/deps/npm/docs/output/commands/npm-shrinkwrap.html b/deps/npm/docs/output/commands/npm-shrinkwrap.html
index abb9c216e6d..761e5b79b26 100644
--- a/deps/npm/docs/output/commands/npm-shrinkwrap.html
+++ b/deps/npm/docs/output/commands/npm-shrinkwrap.html
@@ -186,9 +186,9 @@
-
+
npm-shrinkwrap
- @11.19.1
+ @11.20.0
Lock down dependency versions for publication
diff --git a/deps/npm/docs/output/commands/npm-stage.html b/deps/npm/docs/output/commands/npm-stage.html
index 74c4f7acddf..4ffbe2c9cc0 100644
--- a/deps/npm/docs/output/commands/npm-stage.html
+++ b/deps/npm/docs/output/commands/npm-stage.html
@@ -186,9 +186,9 @@
-
+
npm-stage
- @11.19.1
+ @11.20.0
Stage packages for publishing
@@ -433,7 +433,7 @@ Flags
--provenance |
false |
Boolean |
-When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. |
+When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. When the provenance-file config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped. |
diff --git a/deps/npm/docs/output/commands/npm-star.html b/deps/npm/docs/output/commands/npm-star.html
index 4ba2f61b179..e627cb613ee 100644
--- a/deps/npm/docs/output/commands/npm-star.html
+++ b/deps/npm/docs/output/commands/npm-star.html
@@ -186,9 +186,9 @@
-
+
npm-star
- @11.19.1
+ @11.20.0
Mark your favorite packages
diff --git a/deps/npm/docs/output/commands/npm-stars.html b/deps/npm/docs/output/commands/npm-stars.html
index a1c7c0a4fd9..d87d857cbeb 100644
--- a/deps/npm/docs/output/commands/npm-stars.html
+++ b/deps/npm/docs/output/commands/npm-stars.html
@@ -186,9 +186,9 @@
-
+
npm-stars
- @11.19.1
+ @11.20.0
View packages marked as favorites
diff --git a/deps/npm/docs/output/commands/npm-start.html b/deps/npm/docs/output/commands/npm-start.html
index 063ac6b3d80..d276c536d4e 100644
--- a/deps/npm/docs/output/commands/npm-start.html
+++ b/deps/npm/docs/output/commands/npm-start.html
@@ -186,9 +186,9 @@
-
+
npm-start
- @11.19.1
+ @11.20.0
Start a package
diff --git a/deps/npm/docs/output/commands/npm-stop.html b/deps/npm/docs/output/commands/npm-stop.html
index b4e84d2488d..bb7a86fe6e0 100644
--- a/deps/npm/docs/output/commands/npm-stop.html
+++ b/deps/npm/docs/output/commands/npm-stop.html
@@ -186,9 +186,9 @@
-
+
npm-stop
- @11.19.1
+ @11.20.0
Stop a package
diff --git a/deps/npm/docs/output/commands/npm-team.html b/deps/npm/docs/output/commands/npm-team.html
index c9a7504b91f..1d4fe77056d 100644
--- a/deps/npm/docs/output/commands/npm-team.html
+++ b/deps/npm/docs/output/commands/npm-team.html
@@ -186,9 +186,9 @@
-
+
npm-team
- @11.19.1
+ @11.20.0
Manage organization teams and team memberships
diff --git a/deps/npm/docs/output/commands/npm-test.html b/deps/npm/docs/output/commands/npm-test.html
index bbb30678ba8..22662fa99ad 100644
--- a/deps/npm/docs/output/commands/npm-test.html
+++ b/deps/npm/docs/output/commands/npm-test.html
@@ -186,9 +186,9 @@
-
+
npm-test
- @11.19.1
+ @11.20.0
Test a package
diff --git a/deps/npm/docs/output/commands/npm-token.html b/deps/npm/docs/output/commands/npm-token.html
index 680c2aa534f..7329915528d 100644
--- a/deps/npm/docs/output/commands/npm-token.html
+++ b/deps/npm/docs/output/commands/npm-token.html
@@ -186,9 +186,9 @@
-
+
npm-token
- @11.19.1
+ @11.20.0
Manage your authentication tokens
@@ -268,11 +268,14 @@ orgs
packages-and-scopes-permission
- Default: null
-- Type: null, "read-only", "read-write", or "no-access"
+- Type: null, "read-only", "read-write", "read-write-stage-only", or
+"no-access"
When creating a Granular Access Token with npm token create, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
orgs-permission
- Default: null
diff --git a/deps/npm/docs/output/commands/npm-trust.html b/deps/npm/docs/output/commands/npm-trust.html
index 6d531484035..4f2cd57ecd5 100644
--- a/deps/npm/docs/output/commands/npm-trust.html
+++ b/deps/npm/docs/output/commands/npm-trust.html
@@ -186,9 +186,9 @@
-
+
npm-trust
- @11.19.1
+ @11.20.0
Manage trusted publishing relationships between packages and CI/CD providers
diff --git a/deps/npm/docs/output/commands/npm-undeprecate.html b/deps/npm/docs/output/commands/npm-undeprecate.html
index d5239ca0cac..6bf5195e4f0 100644
--- a/deps/npm/docs/output/commands/npm-undeprecate.html
+++ b/deps/npm/docs/output/commands/npm-undeprecate.html
@@ -186,9 +186,9 @@
-
+
npm-undeprecate
- @11.19.1
+ @11.20.0
Undeprecate a version of a package
diff --git a/deps/npm/docs/output/commands/npm-uninstall.html b/deps/npm/docs/output/commands/npm-uninstall.html
index 26991d034bd..c7bd23fe17f 100644
--- a/deps/npm/docs/output/commands/npm-uninstall.html
+++ b/deps/npm/docs/output/commands/npm-uninstall.html
@@ -186,9 +186,9 @@
-
+
npm-uninstall
- @11.19.1
+ @11.20.0
Remove a package
diff --git a/deps/npm/docs/output/commands/npm-unpublish.html b/deps/npm/docs/output/commands/npm-unpublish.html
index 4fda332a961..80fbe894b17 100644
--- a/deps/npm/docs/output/commands/npm-unpublish.html
+++ b/deps/npm/docs/output/commands/npm-unpublish.html
@@ -186,9 +186,9 @@
-
+
npm-unpublish
- @11.19.1
+ @11.20.0
Remove a package from the registry
diff --git a/deps/npm/docs/output/commands/npm-unstar.html b/deps/npm/docs/output/commands/npm-unstar.html
index 25db54715dd..f061163d223 100644
--- a/deps/npm/docs/output/commands/npm-unstar.html
+++ b/deps/npm/docs/output/commands/npm-unstar.html
@@ -186,9 +186,9 @@
-
+
npm-unstar
- @11.19.1
+ @11.20.0
Remove an item from your favorite packages
diff --git a/deps/npm/docs/output/commands/npm-update.html b/deps/npm/docs/output/commands/npm-update.html
index fff2f70073c..6d8f260b7be 100644
--- a/deps/npm/docs/output/commands/npm-update.html
+++ b/deps/npm/docs/output/commands/npm-update.html
@@ -186,9 +186,9 @@
-
+
npm-update
- @11.19.1
+ @11.20.0
Update packages
@@ -430,6 +430,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
strict-allow-scripts
- Default: false
diff --git a/deps/npm/docs/output/commands/npm-version.html b/deps/npm/docs/output/commands/npm-version.html
index 310abe5db90..22667d199ee 100644
--- a/deps/npm/docs/output/commands/npm-version.html
+++ b/deps/npm/docs/output/commands/npm-version.html
@@ -186,9 +186,9 @@
-
+
npm-version
- @11.19.1
+ @11.20.0
Bump a package version
diff --git a/deps/npm/docs/output/commands/npm-view.html b/deps/npm/docs/output/commands/npm-view.html
index 18f28fe1707..d6892fd94d5 100644
--- a/deps/npm/docs/output/commands/npm-view.html
+++ b/deps/npm/docs/output/commands/npm-view.html
@@ -186,9 +186,9 @@
-
+
npm-view
- @11.19.1
+ @11.20.0
View registry info
diff --git a/deps/npm/docs/output/commands/npm-whoami.html b/deps/npm/docs/output/commands/npm-whoami.html
index 91a7d6e2288..de1960ac172 100644
--- a/deps/npm/docs/output/commands/npm-whoami.html
+++ b/deps/npm/docs/output/commands/npm-whoami.html
@@ -186,9 +186,9 @@
-
+
npm-whoami
- @11.19.1
+ @11.20.0
Display npm username
diff --git a/deps/npm/docs/output/commands/npm.html b/deps/npm/docs/output/commands/npm.html
index 99674e1362d..0f03bc8548e 100644
--- a/deps/npm/docs/output/commands/npm.html
+++ b/deps/npm/docs/output/commands/npm.html
@@ -186,9 +186,9 @@
-
+
npm
- @11.19.1
+ @11.20.0
javascript package manager
@@ -203,7 +203,7 @@ Table of contents
Note: This command is unaware of workspaces.
Version
-11.19.1
+11.20.0
Description
npm is the package manager for the Node JavaScript platform.
It puts modules in place so that node can find them, and manages dependency conflicts intelligently.
diff --git a/deps/npm/docs/output/commands/npx.html b/deps/npm/docs/output/commands/npx.html
index d3cb1e00cc5..80673580a6f 100644
--- a/deps/npm/docs/output/commands/npx.html
+++ b/deps/npm/docs/output/commands/npx.html
@@ -186,9 +186,9 @@
-
+
npx
- @11.19.1
+ @11.20.0
Run a command from a local or remote npm package
diff --git a/deps/npm/docs/output/configuring-npm/folders.html b/deps/npm/docs/output/configuring-npm/folders.html
index 3e86bf9a9ee..edf68a7fda4 100644
--- a/deps/npm/docs/output/configuring-npm/folders.html
+++ b/deps/npm/docs/output/configuring-npm/folders.html
@@ -186,9 +186,9 @@
-
+
Folders
- @11.19.1
+ @11.20.0
Folder structures used by npm
diff --git a/deps/npm/docs/output/configuring-npm/install.html b/deps/npm/docs/output/configuring-npm/install.html
index 610fc057a13..8356ea4bc55 100644
--- a/deps/npm/docs/output/configuring-npm/install.html
+++ b/deps/npm/docs/output/configuring-npm/install.html
@@ -186,9 +186,9 @@
-
+
Install
- @11.19.1
+ @11.20.0
Download and install node and npm
diff --git a/deps/npm/docs/output/configuring-npm/npm-global.html b/deps/npm/docs/output/configuring-npm/npm-global.html
index 3e86bf9a9ee..edf68a7fda4 100644
--- a/deps/npm/docs/output/configuring-npm/npm-global.html
+++ b/deps/npm/docs/output/configuring-npm/npm-global.html
@@ -186,9 +186,9 @@
-
+
Folders
- @11.19.1
+ @11.20.0
Folder structures used by npm
diff --git a/deps/npm/docs/output/configuring-npm/npm-json.html b/deps/npm/docs/output/configuring-npm/npm-json.html
index 97a03a6d617..70ef8ced0fc 100644
--- a/deps/npm/docs/output/configuring-npm/npm-json.html
+++ b/deps/npm/docs/output/configuring-npm/npm-json.html
@@ -186,9 +186,9 @@
-
+
package.json
- @11.19.1
+ @11.20.0
Specifics of npm's package.json handling
diff --git a/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html b/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html
index 134524b16af..eb90cfd59de 100644
--- a/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html
+++ b/deps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.html
@@ -186,9 +186,9 @@
-
+
npm-shrinkwrap.json
- @11.19.1
+ @11.20.0
A publishable lockfile
diff --git a/deps/npm/docs/output/configuring-npm/npmrc.html b/deps/npm/docs/output/configuring-npm/npmrc.html
index a5eb291b57c..462664c7325 100644
--- a/deps/npm/docs/output/configuring-npm/npmrc.html
+++ b/deps/npm/docs/output/configuring-npm/npmrc.html
@@ -186,9 +186,9 @@
-
+
.npmrc
- @11.19.1
+ @11.20.0
The npm config files
diff --git a/deps/npm/docs/output/configuring-npm/package-json.html b/deps/npm/docs/output/configuring-npm/package-json.html
index 97a03a6d617..70ef8ced0fc 100644
--- a/deps/npm/docs/output/configuring-npm/package-json.html
+++ b/deps/npm/docs/output/configuring-npm/package-json.html
@@ -186,9 +186,9 @@
-
+
package.json
- @11.19.1
+ @11.20.0
Specifics of npm's package.json handling
diff --git a/deps/npm/docs/output/configuring-npm/package-lock-json.html b/deps/npm/docs/output/configuring-npm/package-lock-json.html
index 9a4f1631b33..8022b532fa4 100644
--- a/deps/npm/docs/output/configuring-npm/package-lock-json.html
+++ b/deps/npm/docs/output/configuring-npm/package-lock-json.html
@@ -186,9 +186,9 @@
-
+
package-lock.json
- @11.19.1
+ @11.20.0
A manifestation of the manifest
diff --git a/deps/npm/docs/output/using-npm/config.html b/deps/npm/docs/output/using-npm/config.html
index ac5829fba75..457b0d079bd 100644
--- a/deps/npm/docs/output/using-npm/config.html
+++ b/deps/npm/docs/output/using-npm/config.html
@@ -186,9 +186,9 @@
-
+
Config
- @11.19.1
+ @11.20.0
About npm configuration
@@ -406,6 +406,7 @@ allow-scripts
Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. --ignore-scripts and
--dangerously-allow-all-scripts both override this setting.
+This value is not exported to the environment for child processes.
allow-scripts-pending
- Default: false
@@ -1266,11 +1267,14 @@ packages-all
packages-and-scopes-permission
- Default: null
-- Type: null, "read-only", "read-write", or "no-access"
+- Type: null, "read-only", "read-write", "read-write-stage-only", or
+"no-access"
When creating a Granular Access Token with npm token create, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
parseable
- Default: false
@@ -1339,6 +1343,8 @@ provenance
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the provenance-file config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
This config cannot be used with: provenance-file
provenance-file
@@ -1346,6 +1352,8 @@ provenance-file
- Type: Path
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
This config cannot be used with: provenance
proxy
diff --git a/deps/npm/docs/output/using-npm/dependency-selectors.html b/deps/npm/docs/output/using-npm/dependency-selectors.html
index c56b5e6c402..baa45c36cbb 100644
--- a/deps/npm/docs/output/using-npm/dependency-selectors.html
+++ b/deps/npm/docs/output/using-npm/dependency-selectors.html
@@ -186,9 +186,9 @@
-
+
Dependency Selectors
- @11.19.1
+ @11.20.0
Dependency Selector Syntax & Querying
diff --git a/deps/npm/docs/output/using-npm/developers.html b/deps/npm/docs/output/using-npm/developers.html
index 984f28bfe7b..27c9b109d8e 100644
--- a/deps/npm/docs/output/using-npm/developers.html
+++ b/deps/npm/docs/output/using-npm/developers.html
@@ -186,9 +186,9 @@
-
+
Developers
- @11.19.1
+ @11.20.0
Developer guide
diff --git a/deps/npm/docs/output/using-npm/logging.html b/deps/npm/docs/output/using-npm/logging.html
index f6f6dd742f1..08314392eea 100644
--- a/deps/npm/docs/output/using-npm/logging.html
+++ b/deps/npm/docs/output/using-npm/logging.html
@@ -186,9 +186,9 @@
-
+
Logging
- @11.19.1
+ @11.20.0
Why, What & How we Log
diff --git a/deps/npm/docs/output/using-npm/orgs.html b/deps/npm/docs/output/using-npm/orgs.html
index f579fcbbac1..242620475df 100644
--- a/deps/npm/docs/output/using-npm/orgs.html
+++ b/deps/npm/docs/output/using-npm/orgs.html
@@ -186,9 +186,9 @@
-
+
Organizations
- @11.19.1
+ @11.20.0
Working with teams & organizations
diff --git a/deps/npm/docs/output/using-npm/package-spec.html b/deps/npm/docs/output/using-npm/package-spec.html
index 620f470d109..b7adbecf2d5 100644
--- a/deps/npm/docs/output/using-npm/package-spec.html
+++ b/deps/npm/docs/output/using-npm/package-spec.html
@@ -186,9 +186,9 @@
-
+
Package spec
- @11.19.1
+ @11.20.0
Package name specifier
diff --git a/deps/npm/docs/output/using-npm/registry.html b/deps/npm/docs/output/using-npm/registry.html
index e61715c22e4..4da60fd44fa 100644
--- a/deps/npm/docs/output/using-npm/registry.html
+++ b/deps/npm/docs/output/using-npm/registry.html
@@ -186,9 +186,9 @@
-
+
Registry
- @11.19.1
+ @11.20.0
The JavaScript Package Registry
diff --git a/deps/npm/docs/output/using-npm/removal.html b/deps/npm/docs/output/using-npm/removal.html
index 07ee6c06bc4..26f86fd3921 100644
--- a/deps/npm/docs/output/using-npm/removal.html
+++ b/deps/npm/docs/output/using-npm/removal.html
@@ -186,9 +186,9 @@
-
+
Removal
- @11.19.1
+ @11.20.0
Cleaning the slate
diff --git a/deps/npm/docs/output/using-npm/scope.html b/deps/npm/docs/output/using-npm/scope.html
index a08571ebfda..fa268bacf0e 100644
--- a/deps/npm/docs/output/using-npm/scope.html
+++ b/deps/npm/docs/output/using-npm/scope.html
@@ -186,9 +186,9 @@
-
+
Scope
- @11.19.1
+ @11.20.0
Scoped packages
diff --git a/deps/npm/docs/output/using-npm/scripts.html b/deps/npm/docs/output/using-npm/scripts.html
index 4e852304a11..bc7875c2368 100644
--- a/deps/npm/docs/output/using-npm/scripts.html
+++ b/deps/npm/docs/output/using-npm/scripts.html
@@ -186,9 +186,9 @@
-
+
Scripts
- @11.19.1
+ @11.20.0
How npm handles the "scripts" field
diff --git a/deps/npm/docs/output/using-npm/workspaces.html b/deps/npm/docs/output/using-npm/workspaces.html
index ec3d3abed05..412a16b9f03 100644
--- a/deps/npm/docs/output/using-npm/workspaces.html
+++ b/deps/npm/docs/output/using-npm/workspaces.html
@@ -186,9 +186,9 @@
-
+
Workspaces
- @11.19.1
+ @11.20.0
Working with workspaces
diff --git a/deps/npm/lib/commands/token.js b/deps/npm/lib/commands/token.js
index 8f54e9d8725..f3fce31af8d 100644
--- a/deps/npm/lib/commands/token.js
+++ b/deps/npm/lib/commands/token.js
@@ -171,6 +171,25 @@ class Token extends BaseCommand {
const validCIDR = await this.validateCIDRList(cidr)
+ // Warn when creating a token that can publish directly to the registry.
+ // Only 'read-write' package/scope permission grants direct-publish; stage-only
+ // tokens ('read-write-stage-only') stage releases instead, and non-publishing
+ // permissions (read-only/no-access) can't publish at all, so both stay silent.
+ // bypass-2fa is orthogonal — it removes the 2FA requirement but grants no
+ // publish capability on its own — so it is not part of this trigger.
+ if (packagesAndScopesPermission === 'read-write') {
+ // Deprecation notice for direct-publish tokens; see github/npm#15609.
+ log.warn(
+ 'token',
+ 'Creating a token that can publish directly to the registry. ' +
+ 'Consider `--packages-and-scopes-permission=read-write-stage-only` ' +
+ 'instead — with a stage-only token, your releases go to a staging ' +
+ 'queue for you to approve before they go public. Bypass-2FA tokens ' +
+ 'with direct-publish access will stop working in January 2027. ' +
+ 'See https://gh.io/bypass-2fa-tokens-no-longer-publish.'
+ )
+ }
+
/* istanbul ignore if - skip testing read input */
if (!password) {
password = await readUserInfo.password()
diff --git a/deps/npm/lib/utils/allow-scripts-writer.js b/deps/npm/lib/utils/allow-scripts-writer.js
index 6964279f2f2..26d13b164e3 100644
--- a/deps/npm/lib/utils/allow-scripts-writer.js
+++ b/deps/npm/lib/utils/allow-scripts-writer.js
@@ -2,6 +2,7 @@ const npa = require('npm-package-arg')
const { log } = require('proc-log')
const {
getTrustedRegistryIdentity,
+ matchFileOrDir,
resolvedSourceSpecs,
} = require('@npmcli/arborist/lib/script-allowed.js')
@@ -150,7 +151,7 @@ const isNameOnlyKey = (key) => {
const keyTargetsNode = (key, node) => {
let parsed
try {
- parsed = npa(key)
+ parsed = npa(key, node?.root?.path)
} catch {
return false
}
@@ -179,6 +180,7 @@ const keyTargetsNode = (key, node) => {
}
case 'file':
case 'directory':
+ return matchFileOrDir(node, parsed)
case 'remote':
return resolvedSourceSpecs(node)
.some(resolved => resolved === parsed.saveSpec || resolved === parsed.fetchSpec)
diff --git a/deps/npm/lib/utils/key-values.js b/deps/npm/lib/utils/key-values.js
index cf54304da6b..ec9f4098931 100644
--- a/deps/npm/lib/utils/key-values.js
+++ b/deps/npm/lib/utils/key-values.js
@@ -26,11 +26,23 @@ function logObject (values, { chalk, json, predicate = defaultPredicate }) {
}
function logStageItem (item, { chalk }) {
- const { id, packageName, version, tag, createdAt, actor, actorType, shasum, ...rest } = item
+ const {
+ id,
+ packageName,
+ version,
+ tag,
+ createdAt,
+ actor,
+ actorType,
+ shasum,
+ status,
+ ...rest
+ } = item
logObject({
id,
'package name': packageName,
version,
+ status,
tag,
'date staged': createdAt,
'staged by': actorType ? `${actor} (${actorType})` : actor,
diff --git a/deps/npm/lib/utils/oidc.js b/deps/npm/lib/utils/oidc.js
index 00f32c64262..203aaf3143a 100644
--- a/deps/npm/lib/utils/oidc.js
+++ b/deps/npm/lib/utils/oidc.js
@@ -143,8 +143,9 @@ async function oidc ({ packageName, registry, opts, config }) {
try {
const isDefaultProvenance = config.isDefault('provenance')
- // CircleCI doesn't support provenance yet, so skip the auto-enable logic
- if (isDefaultProvenance && !ciInfo.CIRCLE) {
+ // CircleCI doesn't support provenance yet, so skip the auto-enable logic.
+ // An explicitly provided provenance file always takes precedence over auto-generated provenance
+ if (isDefaultProvenance && !ciInfo.CIRCLE && !opts.provenanceFile) {
const [headerB64, payloadB64] = idToken.split('.')
if (headerB64 && payloadB64) {
const payloadJson = Buffer.from(payloadB64, 'base64').toString('utf8')
@@ -158,7 +159,6 @@ async function oidc ({ packageName, registry, opts, config }) {
if (visibility?.public) {
log.verbose('oidc', `Enabling provenance`)
opts.provenance = true
- config.set('provenance', true, 'user')
}
}
}
diff --git a/deps/npm/lib/utils/reify-output.js b/deps/npm/lib/utils/reify-output.js
index fa229a318d2..aa32e116f42 100644
--- a/deps/npm/lib/utils/reify-output.js
+++ b/deps/npm/lib/utils/reify-output.js
@@ -44,7 +44,8 @@ const reifyOutput = (npm, arb, extras = {}) => {
}
if (diff) {
- const showDiff = npm.config.get('dry-run') || npm.config.get('long')
+ const showDiff = !npm.flatOptions.json &&
+ (npm.config.get('dry-run') || npm.config.get('long'))
const chalk = npm.chalk
depth({
@@ -221,7 +222,7 @@ const packagesChangedMessage = (npm, { added, removed, changed, audited }) => {
}
const packagesFundingMessage = (npm, { funding }) => {
- if (!funding) {
+ if (!funding || npm.global) {
return
}
diff --git a/deps/npm/man/man1/npm-access.1 b/deps/npm/man/man1/npm-access.1
index 435819623db..ce8b4b2347e 100644
--- a/deps/npm/man/man1/npm-access.1
+++ b/deps/npm/man/man1/npm-access.1
@@ -1,4 +1,4 @@
-.TH "NPM-ACCESS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ACCESS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-access\fR - Set access level on published packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-adduser.1 b/deps/npm/man/man1/npm-adduser.1
index 5cc62878424..99c40da9021 100644
--- a/deps/npm/man/man1/npm-adduser.1
+++ b/deps/npm/man/man1/npm-adduser.1
@@ -1,4 +1,4 @@
-.TH "NPM-ADDUSER" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ADDUSER" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-adduser\fR - Add a registry user account
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-approve-scripts.1 b/deps/npm/man/man1/npm-approve-scripts.1
index f874e752ab9..ea3b8559af3 100644
--- a/deps/npm/man/man1/npm-approve-scripts.1
+++ b/deps/npm/man/man1/npm-approve-scripts.1
@@ -1,4 +1,4 @@
-.TH "NPM-APPROVE-SCRIPTS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-APPROVE-SCRIPTS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-approve-scripts\fR - Approve install scripts for specific dependencies
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-audit.1 b/deps/npm/man/man1/npm-audit.1
index 8c9815292ae..d66317be2a6 100644
--- a/deps/npm/man/man1/npm-audit.1
+++ b/deps/npm/man/man1/npm-audit.1
@@ -1,4 +1,4 @@
-.TH "NPM-AUDIT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-AUDIT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-audit\fR - Run a security audit
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-bugs.1 b/deps/npm/man/man1/npm-bugs.1
index 0113cf310fd..be2e0ec4073 100644
--- a/deps/npm/man/man1/npm-bugs.1
+++ b/deps/npm/man/man1/npm-bugs.1
@@ -1,4 +1,4 @@
-.TH "NPM-BUGS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-BUGS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-bugs\fR - Report bugs for a package in a web browser
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-cache.1 b/deps/npm/man/man1/npm-cache.1
index 71eaeccf613..08a904d5e7a 100644
--- a/deps/npm/man/man1/npm-cache.1
+++ b/deps/npm/man/man1/npm-cache.1
@@ -1,4 +1,4 @@
-.TH "NPM-CACHE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-CACHE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-cache\fR - Manipulates packages cache
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ci.1 b/deps/npm/man/man1/npm-ci.1
index 2e544d6dfa8..b0611e9a121 100644
--- a/deps/npm/man/man1/npm-ci.1
+++ b/deps/npm/man/man1/npm-ci.1
@@ -1,4 +1,4 @@
-.TH "NPM-CI" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-CI" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ci\fR - Clean install a project
.SS "Synopsis"
@@ -232,6 +232,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-completion.1 b/deps/npm/man/man1/npm-completion.1
index d5cefe61d0c..b84d2dc1fd6 100644
--- a/deps/npm/man/man1/npm-completion.1
+++ b/deps/npm/man/man1/npm-completion.1
@@ -1,4 +1,4 @@
-.TH "NPM-COMPLETION" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-COMPLETION" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-completion\fR - Tab Completion for npm
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-config.1 b/deps/npm/man/man1/npm-config.1
index b0ef989fe72..2bbcce24963 100644
--- a/deps/npm/man/man1/npm-config.1
+++ b/deps/npm/man/man1/npm-config.1
@@ -1,4 +1,4 @@
-.TH "NPM-CONFIG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-CONFIG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-config\fR - Manage the npm configuration files
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-dedupe.1 b/deps/npm/man/man1/npm-dedupe.1
index 1fa8e34027f..f7f3cfc935f 100644
--- a/deps/npm/man/man1/npm-dedupe.1
+++ b/deps/npm/man/man1/npm-dedupe.1
@@ -1,4 +1,4 @@
-.TH "NPM-DEDUPE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DEDUPE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-dedupe\fR - Reduce duplication in the package tree
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-deny-scripts.1 b/deps/npm/man/man1/npm-deny-scripts.1
index 70fb96d6fcd..0477e41503b 100644
--- a/deps/npm/man/man1/npm-deny-scripts.1
+++ b/deps/npm/man/man1/npm-deny-scripts.1
@@ -1,4 +1,4 @@
-.TH "NPM-DENY-SCRIPTS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DENY-SCRIPTS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-deny-scripts\fR - Deny install scripts for specific dependencies
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-deprecate.1 b/deps/npm/man/man1/npm-deprecate.1
index e07bd5829ef..4caab6c3ad9 100644
--- a/deps/npm/man/man1/npm-deprecate.1
+++ b/deps/npm/man/man1/npm-deprecate.1
@@ -1,4 +1,4 @@
-.TH "NPM-DEPRECATE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DEPRECATE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-deprecate\fR - Deprecate a version of a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-diff.1 b/deps/npm/man/man1/npm-diff.1
index 42c3903bd46..e2122d844c6 100644
--- a/deps/npm/man/man1/npm-diff.1
+++ b/deps/npm/man/man1/npm-diff.1
@@ -1,4 +1,4 @@
-.TH "NPM-DIFF" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DIFF" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-diff\fR - The registry diff command
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-dist-tag.1 b/deps/npm/man/man1/npm-dist-tag.1
index 8ebc625273c..7a85fbab68d 100644
--- a/deps/npm/man/man1/npm-dist-tag.1
+++ b/deps/npm/man/man1/npm-dist-tag.1
@@ -1,4 +1,4 @@
-.TH "NPM-DIST-TAG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DIST-TAG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-dist-tag\fR - Modify package distribution tags
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-docs.1 b/deps/npm/man/man1/npm-docs.1
index 26fa80d54d5..ef586a86d27 100644
--- a/deps/npm/man/man1/npm-docs.1
+++ b/deps/npm/man/man1/npm-docs.1
@@ -1,4 +1,4 @@
-.TH "NPM-DOCS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DOCS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-docs\fR - Open documentation for a package in a web browser
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-doctor.1 b/deps/npm/man/man1/npm-doctor.1
index f5b750fd6a3..05c5c4d9dcc 100644
--- a/deps/npm/man/man1/npm-doctor.1
+++ b/deps/npm/man/man1/npm-doctor.1
@@ -1,4 +1,4 @@
-.TH "NPM-DOCTOR" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-DOCTOR" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-doctor\fR - Check the health of your npm environment
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-edit.1 b/deps/npm/man/man1/npm-edit.1
index 5055e6feaa5..7bf09de5223 100644
--- a/deps/npm/man/man1/npm-edit.1
+++ b/deps/npm/man/man1/npm-edit.1
@@ -1,4 +1,4 @@
-.TH "NPM-EDIT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EDIT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-edit\fR - Edit an installed package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-exec.1 b/deps/npm/man/man1/npm-exec.1
index 5ae0a77e288..b3132e062c7 100644
--- a/deps/npm/man/man1/npm-exec.1
+++ b/deps/npm/man/man1/npm-exec.1
@@ -1,4 +1,4 @@
-.TH "NPM-EXEC" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EXEC" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-exec\fR - Run a command from a local or remote npm package
.SS "Synopsis"
@@ -181,6 +181,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-explain.1 b/deps/npm/man/man1/npm-explain.1
index 7869082b6c6..1abb4a0e94d 100644
--- a/deps/npm/man/man1/npm-explain.1
+++ b/deps/npm/man/man1/npm-explain.1
@@ -1,4 +1,4 @@
-.TH "NPM-EXPLAIN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EXPLAIN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-explain\fR - Explain installed packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-explore.1 b/deps/npm/man/man1/npm-explore.1
index df1fd2dc651..fc45ae27ae2 100644
--- a/deps/npm/man/man1/npm-explore.1
+++ b/deps/npm/man/man1/npm-explore.1
@@ -1,4 +1,4 @@
-.TH "NPM-EXPLORE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-EXPLORE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-explore\fR - Browse an installed package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-find-dupes.1 b/deps/npm/man/man1/npm-find-dupes.1
index f1f3970dd1d..5804305f900 100644
--- a/deps/npm/man/man1/npm-find-dupes.1
+++ b/deps/npm/man/man1/npm-find-dupes.1
@@ -1,4 +1,4 @@
-.TH "NPM-FIND-DUPES" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-FIND-DUPES" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-find-dupes\fR - Find duplication in the package tree
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-fund.1 b/deps/npm/man/man1/npm-fund.1
index 88bfe299c31..10eca78547a 100644
--- a/deps/npm/man/man1/npm-fund.1
+++ b/deps/npm/man/man1/npm-fund.1
@@ -1,4 +1,4 @@
-.TH "NPM-FUND" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-FUND" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-fund\fR - Retrieve funding information
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-get.1 b/deps/npm/man/man1/npm-get.1
index 7982d28e324..b67dfc6ed7e 100644
--- a/deps/npm/man/man1/npm-get.1
+++ b/deps/npm/man/man1/npm-get.1
@@ -1,4 +1,4 @@
-.TH "NPM-GET" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-GET" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-get\fR - Get a value from the npm configuration
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-help-search.1 b/deps/npm/man/man1/npm-help-search.1
index e7c7d97ebce..44c464dc229 100644
--- a/deps/npm/man/man1/npm-help-search.1
+++ b/deps/npm/man/man1/npm-help-search.1
@@ -1,4 +1,4 @@
-.TH "NPM-HELP-SEARCH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-HELP-SEARCH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-help-search\fR - Search npm help documentation
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-help.1 b/deps/npm/man/man1/npm-help.1
index 7725a82d09c..6c0dac1a9b9 100644
--- a/deps/npm/man/man1/npm-help.1
+++ b/deps/npm/man/man1/npm-help.1
@@ -1,4 +1,4 @@
-.TH "NPM-HELP" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-HELP" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-help\fR - Get help on npm
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-init.1 b/deps/npm/man/man1/npm-init.1
index bd984db7d20..3774607b93d 100644
--- a/deps/npm/man/man1/npm-init.1
+++ b/deps/npm/man/man1/npm-init.1
@@ -1,4 +1,4 @@
-.TH "NPM-INIT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INIT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-init\fR - Create a package.json file
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-install-ci-test.1 b/deps/npm/man/man1/npm-install-ci-test.1
index b477b4a8b0e..0725d13e7a9 100644
--- a/deps/npm/man/man1/npm-install-ci-test.1
+++ b/deps/npm/man/man1/npm-install-ci-test.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL-CI-TEST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL-CI-TEST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install-ci-test\fR - Install a project with a clean slate and run tests
.SS "Synopsis"
@@ -180,6 +180,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-install-scripts.1 b/deps/npm/man/man1/npm-install-scripts.1
index b634903e3ec..9d4076cd8fd 100644
--- a/deps/npm/man/man1/npm-install-scripts.1
+++ b/deps/npm/man/man1/npm-install-scripts.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL-SCRIPTS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL-SCRIPTS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install-scripts\fR - Manage install-script approvals for dependencies
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-install-test.1 b/deps/npm/man/man1/npm-install-test.1
index d6774940ea2..f552f5d3935 100644
--- a/deps/npm/man/man1/npm-install-test.1
+++ b/deps/npm/man/man1/npm-install-test.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL-TEST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL-TEST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install-test\fR - Install package(s) and run tests
.SS "Synopsis"
@@ -257,6 +257,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-install.1 b/deps/npm/man/man1/npm-install.1
index c6ca10ab642..06e7759a10f 100644
--- a/deps/npm/man/man1/npm-install.1
+++ b/deps/npm/man/man1/npm-install.1
@@ -1,4 +1,4 @@
-.TH "NPM-INSTALL" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-INSTALL" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-install\fR - Install a package
.SS "Synopsis"
@@ -647,6 +647,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-link.1 b/deps/npm/man/man1/npm-link.1
index ea482b872b8..9e03ea12635 100644
--- a/deps/npm/man/man1/npm-link.1
+++ b/deps/npm/man/man1/npm-link.1
@@ -1,4 +1,4 @@
-.TH "NPM-LINK" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LINK" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-link\fR - Symlink a package folder
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ll.1 b/deps/npm/man/man1/npm-ll.1
index 136777491e0..8fd1de7651e 100644
--- a/deps/npm/man/man1/npm-ll.1
+++ b/deps/npm/man/man1/npm-ll.1
@@ -1,4 +1,4 @@
-.TH "NPM-LL" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LL" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ll\fR - List installed packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-login.1 b/deps/npm/man/man1/npm-login.1
index ecc47d745de..aef0a9f0387 100644
--- a/deps/npm/man/man1/npm-login.1
+++ b/deps/npm/man/man1/npm-login.1
@@ -1,4 +1,4 @@
-.TH "NPM-LOGIN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LOGIN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-login\fR - Login to a registry user account
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-logout.1 b/deps/npm/man/man1/npm-logout.1
index 22d86e96586..941e7fdc0a5 100644
--- a/deps/npm/man/man1/npm-logout.1
+++ b/deps/npm/man/man1/npm-logout.1
@@ -1,4 +1,4 @@
-.TH "NPM-LOGOUT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LOGOUT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-logout\fR - Log out of the registry
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ls.1 b/deps/npm/man/man1/npm-ls.1
index 52224d908c2..96705c0c5aa 100644
--- a/deps/npm/man/man1/npm-ls.1
+++ b/deps/npm/man/man1/npm-ls.1
@@ -1,4 +1,4 @@
-.TH "NPM-LS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-LS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ls\fR - List installed packages
.SS "Synopsis"
@@ -20,7 +20,7 @@ Positional arguments are \fBname@version-range\fR identifiers, which will limit
.P
.RS 2
.nf
-npm@11.19.1 /path/to/npm
+npm@11.20.0 /path/to/npm
└─┬ init-package-json@0.0.4
└── promzard@0.1.5
.fi
diff --git a/deps/npm/man/man1/npm-org.1 b/deps/npm/man/man1/npm-org.1
index 4b7592722da..38b8cdcf245 100644
--- a/deps/npm/man/man1/npm-org.1
+++ b/deps/npm/man/man1/npm-org.1
@@ -1,4 +1,4 @@
-.TH "NPM-ORG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ORG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-org\fR - Manage orgs
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-outdated.1 b/deps/npm/man/man1/npm-outdated.1
index f83acac0d64..2995ee08434 100644
--- a/deps/npm/man/man1/npm-outdated.1
+++ b/deps/npm/man/man1/npm-outdated.1
@@ -1,4 +1,4 @@
-.TH "NPM-OUTDATED" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-OUTDATED" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-outdated\fR - Check for outdated packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-owner.1 b/deps/npm/man/man1/npm-owner.1
index 68a98e734ef..a1644110b92 100644
--- a/deps/npm/man/man1/npm-owner.1
+++ b/deps/npm/man/man1/npm-owner.1
@@ -1,4 +1,4 @@
-.TH "NPM-OWNER" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-OWNER" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-owner\fR - Manage package owners
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-pack.1 b/deps/npm/man/man1/npm-pack.1
index 58b82df2663..ea2ef910637 100644
--- a/deps/npm/man/man1/npm-pack.1
+++ b/deps/npm/man/man1/npm-pack.1
@@ -1,4 +1,4 @@
-.TH "NPM-PACK" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PACK" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-pack\fR - Create a tarball from a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-ping.1 b/deps/npm/man/man1/npm-ping.1
index 4df93fbd993..d3590506a26 100644
--- a/deps/npm/man/man1/npm-ping.1
+++ b/deps/npm/man/man1/npm-ping.1
@@ -1,4 +1,4 @@
-.TH "NPM-PING" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PING" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-ping\fR - Ping npm registry
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-pkg.1 b/deps/npm/man/man1/npm-pkg.1
index ad11f73873a..3c72c3739a5 100644
--- a/deps/npm/man/man1/npm-pkg.1
+++ b/deps/npm/man/man1/npm-pkg.1
@@ -1,4 +1,4 @@
-.TH "NPM-PKG" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PKG" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-pkg\fR - Manages your package.json
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-prefix.1 b/deps/npm/man/man1/npm-prefix.1
index 6c990176088..1b5cf9e8e5b 100644
--- a/deps/npm/man/man1/npm-prefix.1
+++ b/deps/npm/man/man1/npm-prefix.1
@@ -1,4 +1,4 @@
-.TH "NPM-PREFIX" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PREFIX" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-prefix\fR - Display prefix
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-profile.1 b/deps/npm/man/man1/npm-profile.1
index 0d5d54620f7..256f451dc45 100644
--- a/deps/npm/man/man1/npm-profile.1
+++ b/deps/npm/man/man1/npm-profile.1
@@ -1,4 +1,4 @@
-.TH "NPM-PROFILE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PROFILE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-profile\fR - Change settings on your registry profile
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-prune.1 b/deps/npm/man/man1/npm-prune.1
index 8f67ca9384f..8c2823dc7a8 100644
--- a/deps/npm/man/man1/npm-prune.1
+++ b/deps/npm/man/man1/npm-prune.1
@@ -1,4 +1,4 @@
-.TH "NPM-PRUNE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PRUNE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-prune\fR - Remove extraneous packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-publish.1 b/deps/npm/man/man1/npm-publish.1
index 4e738ab0bbd..5b89d5a1020 100644
--- a/deps/npm/man/man1/npm-publish.1
+++ b/deps/npm/man/man1/npm-publish.1
@@ -1,4 +1,4 @@
-.TH "NPM-PUBLISH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-PUBLISH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-publish\fR - Publish a package
.SS "Synopsis"
@@ -225,6 +225,8 @@ Type: Boolean
.P
When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from.
.P
+When the \fBprovenance-file\fR config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped.
+.P
This config cannot be used with: \fBprovenance-file\fR
.SS "\fBprovenance-file\fR"
.RS 0
@@ -237,6 +239,8 @@ Type: Path
.P
When publishing, the provenance bundle at the given path will be used.
.P
+This takes precedence over automatic provenance generation in trusted publishing flows.
+.P
This config cannot be used with: \fBprovenance\fR
.SS "See Also"
.RS 0
diff --git a/deps/npm/man/man1/npm-query.1 b/deps/npm/man/man1/npm-query.1
index 334fc20660e..244e8b96469 100644
--- a/deps/npm/man/man1/npm-query.1
+++ b/deps/npm/man/man1/npm-query.1
@@ -1,4 +1,4 @@
-.TH "NPM-QUERY" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-QUERY" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-query\fR - Dependency selector query
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-rebuild.1 b/deps/npm/man/man1/npm-rebuild.1
index 6a09726529b..3fb1df08bc5 100644
--- a/deps/npm/man/man1/npm-rebuild.1
+++ b/deps/npm/man/man1/npm-rebuild.1
@@ -1,4 +1,4 @@
-.TH "NPM-REBUILD" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-REBUILD" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-rebuild\fR - Rebuild a package
.SS "Synopsis"
@@ -115,6 +115,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-repo.1 b/deps/npm/man/man1/npm-repo.1
index 5ff08e9eeb4..a68132d520b 100644
--- a/deps/npm/man/man1/npm-repo.1
+++ b/deps/npm/man/man1/npm-repo.1
@@ -1,4 +1,4 @@
-.TH "NPM-REPO" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-REPO" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-repo\fR - Open package repository page in the browser
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-restart.1 b/deps/npm/man/man1/npm-restart.1
index d4f5f0d3df1..8d1deb3ff11 100644
--- a/deps/npm/man/man1/npm-restart.1
+++ b/deps/npm/man/man1/npm-restart.1
@@ -1,4 +1,4 @@
-.TH "NPM-RESTART" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-RESTART" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-restart\fR - Restart a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-root.1 b/deps/npm/man/man1/npm-root.1
index ecd0c64ef6b..7090dca70da 100644
--- a/deps/npm/man/man1/npm-root.1
+++ b/deps/npm/man/man1/npm-root.1
@@ -1,4 +1,4 @@
-.TH "NPM-ROOT" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-ROOT" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-root\fR - Display npm root
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-run.1 b/deps/npm/man/man1/npm-run.1
index 8aadcceff7c..fe72ce5905a 100644
--- a/deps/npm/man/man1/npm-run.1
+++ b/deps/npm/man/man1/npm-run.1
@@ -1,4 +1,4 @@
-.TH "NPM-RUN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-RUN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-run\fR - Run arbitrary package scripts
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-sbom.1 b/deps/npm/man/man1/npm-sbom.1
index f694d642f9a..531b802b659 100644
--- a/deps/npm/man/man1/npm-sbom.1
+++ b/deps/npm/man/man1/npm-sbom.1
@@ -1,4 +1,4 @@
-.TH "NPM-SBOM" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SBOM" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-sbom\fR - Generate a Software Bill of Materials (SBOM)
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-search.1 b/deps/npm/man/man1/npm-search.1
index 969d0e78490..bf07a91bbc1 100644
--- a/deps/npm/man/man1/npm-search.1
+++ b/deps/npm/man/man1/npm-search.1
@@ -1,4 +1,4 @@
-.TH "NPM-SEARCH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SEARCH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-search\fR - Search for packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-set.1 b/deps/npm/man/man1/npm-set.1
index 4deaf8e01ac..4478b11a645 100644
--- a/deps/npm/man/man1/npm-set.1
+++ b/deps/npm/man/man1/npm-set.1
@@ -1,4 +1,4 @@
-.TH "NPM-SET" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SET" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-set\fR - Set a value in the npm configuration
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-shrinkwrap.1 b/deps/npm/man/man1/npm-shrinkwrap.1
index 35caa20c3dc..48949aa9d49 100644
--- a/deps/npm/man/man1/npm-shrinkwrap.1
+++ b/deps/npm/man/man1/npm-shrinkwrap.1
@@ -1,4 +1,4 @@
-.TH "NPM-SHRINKWRAP" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SHRINKWRAP" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-shrinkwrap\fR - Lock down dependency versions for publication
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-stage.1 b/deps/npm/man/man1/npm-stage.1
index 8c201605213..0f2df23539c 100644
--- a/deps/npm/man/man1/npm-stage.1
+++ b/deps/npm/man/man1/npm-stage.1
@@ -1,4 +1,4 @@
-.TH "NPM-STAGE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STAGE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-stage\fR - Stage packages for publishing
.SS "Synopsis"
@@ -101,7 +101,7 @@ npm stage publish
.RE
.SS "Flags"
.P
-| Flag | Default | Type | Description | | --- | --- | --- | --- | | \fB--tag\fR | "latest" | String | If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag. It is the tag added to the package@version specified in the \fBnpm dist-tag add\fR command, if no explicit tag is given. When used by the \fBnpm diff\fR command, this is the tag used to fetch the tarball that will be compared with the local files by default. If used in the \fBnpm publish\fR command, this is the tag that will be added to the package submitted to the registry. | | \fB--access\fR | 'public' for new packages, existing packages it will not change the current level | null, "restricted", "public", or "private" | If you do not want your scoped package to be publicly viewable (and installable) set \fB--access=restricted\fR. Unscoped packages cannot be set to \fBrestricted\fR. Note: This defaults to not changing the current access level for existing packages. Specifying a value of \fBrestricted\fR or \fBpublic\fR during publish will change the access for an existing package the same way that \fBnpm access set status\fR would. The value \fBprivate\fR is an alias for \fBrestricted\fR. | | \fB--dry-run\fR | false | Boolean | Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, \fBinstall\fR, \fBupdate\fR, \fBdedupe\fR, \fBuninstall\fR, as well as \fBpack\fR and \fBpublish\fR. Note: This is NOT honored by other network related commands, eg \fBdist-tags\fR, \fBowner\fR, etc. | | \fB--otp\fR | null | null or String | This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with \fBnpm access\fR. If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one. | | \fB--workspace\fR, \fB-w\fR | | String (can be set multiple times) | Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the \fBworkspace\fR config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the \fBnpm init\fR command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. | | \fB--workspaces\fR | null | null or Boolean | Set to true to run the command in the context of \fBall\fR configured workspaces. Explicitly setting this to false will cause commands like \fBinstall\fR to ignore workspaces altogether. When not set explicitly: - Commands that operate on the \fBnode_modules\fR tree (install, update, etc.) will link workspaces into the \fBnode_modules\fR folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, \fIunless\fR one or more workspaces are specified in the \fBworkspace\fR config. | | \fB--include-workspace-root\fR | false | Boolean | Include the workspace root when workspaces are enabled for a command. When false, specifying individual workspaces via the \fBworkspace\fR config, or all workspaces via the \fBworkspaces\fR flag, will cause npm to operate only on the specified workspaces, and not on the root project. | | \fB--provenance\fR | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. |
+| Flag | Default | Type | Description | | --- | --- | --- | --- | | \fB--tag\fR | "latest" | String | If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag. It is the tag added to the package@version specified in the \fBnpm dist-tag add\fR command, if no explicit tag is given. When used by the \fBnpm diff\fR command, this is the tag used to fetch the tarball that will be compared with the local files by default. If used in the \fBnpm publish\fR command, this is the tag that will be added to the package submitted to the registry. | | \fB--access\fR | 'public' for new packages, existing packages it will not change the current level | null, "restricted", "public", or "private" | If you do not want your scoped package to be publicly viewable (and installable) set \fB--access=restricted\fR. Unscoped packages cannot be set to \fBrestricted\fR. Note: This defaults to not changing the current access level for existing packages. Specifying a value of \fBrestricted\fR or \fBpublic\fR during publish will change the access for an existing package the same way that \fBnpm access set status\fR would. The value \fBprivate\fR is an alias for \fBrestricted\fR. | | \fB--dry-run\fR | false | Boolean | Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, \fBinstall\fR, \fBupdate\fR, \fBdedupe\fR, \fBuninstall\fR, as well as \fBpack\fR and \fBpublish\fR. Note: This is NOT honored by other network related commands, eg \fBdist-tags\fR, \fBowner\fR, etc. | | \fB--otp\fR | null | null or String | This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with \fBnpm access\fR. If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one. | | \fB--workspace\fR, \fB-w\fR | | String (can be set multiple times) | Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option. Valid values for the \fBworkspace\fR config are either: * Workspace names * Path to a workspace directory * Path to a parent workspace directory (will result in selecting all workspaces within that folder) When set for the \fBnpm init\fR command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project. | | \fB--workspaces\fR | null | null or Boolean | Set to true to run the command in the context of \fBall\fR configured workspaces. Explicitly setting this to false will cause commands like \fBinstall\fR to ignore workspaces altogether. When not set explicitly: - Commands that operate on the \fBnode_modules\fR tree (install, update, etc.) will link workspaces into the \fBnode_modules\fR folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, \fIunless\fR one or more workspaces are specified in the \fBworkspace\fR config. | | \fB--include-workspace-root\fR | false | Boolean | Include the workspace root when workspaces are enabled for a command. When false, specifying individual workspaces via the \fBworkspace\fR config, or all workspaces via the \fBworkspaces\fR flag, will cause npm to operate only on the specified workspaces, and not on the root project. | | \fB--provenance\fR | false | Boolean | When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from. When the \fBprovenance-file\fR config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped. |
.SS "\fBnpm stage list\fR"
.P
List all staged package versions
diff --git a/deps/npm/man/man1/npm-star.1 b/deps/npm/man/man1/npm-star.1
index a2191c120e3..1c05090c3a2 100644
--- a/deps/npm/man/man1/npm-star.1
+++ b/deps/npm/man/man1/npm-star.1
@@ -1,4 +1,4 @@
-.TH "NPM-STAR" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STAR" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-star\fR - Mark your favorite packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-stars.1 b/deps/npm/man/man1/npm-stars.1
index aca98ed914a..27ee3c674f0 100644
--- a/deps/npm/man/man1/npm-stars.1
+++ b/deps/npm/man/man1/npm-stars.1
@@ -1,4 +1,4 @@
-.TH "NPM-STARS" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STARS" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-stars\fR - View packages marked as favorites
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-start.1 b/deps/npm/man/man1/npm-start.1
index d2f3b4d87cc..17c42ab4023 100644
--- a/deps/npm/man/man1/npm-start.1
+++ b/deps/npm/man/man1/npm-start.1
@@ -1,4 +1,4 @@
-.TH "NPM-START" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-START" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-start\fR - Start a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-stop.1 b/deps/npm/man/man1/npm-stop.1
index 7896dd6acd1..1d544669cbf 100644
--- a/deps/npm/man/man1/npm-stop.1
+++ b/deps/npm/man/man1/npm-stop.1
@@ -1,4 +1,4 @@
-.TH "NPM-STOP" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-STOP" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-stop\fR - Stop a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-team.1 b/deps/npm/man/man1/npm-team.1
index 21ccc530ad8..1d42f0f514c 100644
--- a/deps/npm/man/man1/npm-team.1
+++ b/deps/npm/man/man1/npm-team.1
@@ -1,4 +1,4 @@
-.TH "NPM-TEAM" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TEAM" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-team\fR - Manage organization teams and team memberships
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-test.1 b/deps/npm/man/man1/npm-test.1
index 8cae879d829..8136624750b 100644
--- a/deps/npm/man/man1/npm-test.1
+++ b/deps/npm/man/man1/npm-test.1
@@ -1,4 +1,4 @@
-.TH "NPM-TEST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TEST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-test\fR - Test a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-token.1 b/deps/npm/man/man1/npm-token.1
index fc82daf8d0c..dafb3148e68 100644
--- a/deps/npm/man/man1/npm-token.1
+++ b/deps/npm/man/man1/npm-token.1
@@ -1,4 +1,4 @@
-.TH "NPM-TOKEN" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TOKEN" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-token\fR - Manage your authentication tokens
.SS "Synopsis"
@@ -104,11 +104,11 @@ When creating a Granular Access Token with \fBnpm token create\fR, this limits t
.IP \(bu 4
Default: null
.IP \(bu 4
-Type: null, "read-only", "read-write", or "no-access"
+Type: null, "read-only", "read-write", "read-write-stage-only", or "no-access"
.RE 0
.P
-When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", or "no-access".
+When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", "read-write-stage-only", or "no-access". "read-write-stage-only" grants publish access that stages releases instead of publishing them directly.
.SS "\fBorgs-permission\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-trust.1 b/deps/npm/man/man1/npm-trust.1
index fce69eb33b7..87d202f3cef 100644
--- a/deps/npm/man/man1/npm-trust.1
+++ b/deps/npm/man/man1/npm-trust.1
@@ -1,4 +1,4 @@
-.TH "NPM-TRUST" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-TRUST" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-trust\fR - Manage trusted publishing relationships between packages and CI/CD providers
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-undeprecate.1 b/deps/npm/man/man1/npm-undeprecate.1
index 11f91ee9b91..6b3b29e1e56 100644
--- a/deps/npm/man/man1/npm-undeprecate.1
+++ b/deps/npm/man/man1/npm-undeprecate.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNDEPRECATE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNDEPRECATE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-undeprecate\fR - Undeprecate a version of a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-uninstall.1 b/deps/npm/man/man1/npm-uninstall.1
index b9ff997229d..896258939ad 100644
--- a/deps/npm/man/man1/npm-uninstall.1
+++ b/deps/npm/man/man1/npm-uninstall.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNINSTALL" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNINSTALL" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-uninstall\fR - Remove a package
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-unpublish.1 b/deps/npm/man/man1/npm-unpublish.1
index 5bbb86e8c8f..f99202071c0 100644
--- a/deps/npm/man/man1/npm-unpublish.1
+++ b/deps/npm/man/man1/npm-unpublish.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNPUBLISH" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNPUBLISH" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-unpublish\fR - Remove a package from the registry
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-unstar.1 b/deps/npm/man/man1/npm-unstar.1
index 0d0e2f2c9e6..60bf9fea8bd 100644
--- a/deps/npm/man/man1/npm-unstar.1
+++ b/deps/npm/man/man1/npm-unstar.1
@@ -1,4 +1,4 @@
-.TH "NPM-UNSTAR" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UNSTAR" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-unstar\fR - Remove an item from your favorite packages
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-update.1 b/deps/npm/man/man1/npm-update.1
index 4f5e015b20d..3e13678d0b9 100644
--- a/deps/npm/man/man1/npm-update.1
+++ b/deps/npm/man/man1/npm-update.1
@@ -1,4 +1,4 @@
-.TH "NPM-UPDATE" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-UPDATE" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-update\fR - Update packages
.SS "Synopsis"
@@ -293,6 +293,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBstrict-allow-scripts\fR"
.RS 0
.IP \(bu 4
diff --git a/deps/npm/man/man1/npm-version.1 b/deps/npm/man/man1/npm-version.1
index c15a0d19acf..064e3a0b752 100644
--- a/deps/npm/man/man1/npm-version.1
+++ b/deps/npm/man/man1/npm-version.1
@@ -1,4 +1,4 @@
-.TH "NPM-VERSION" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-VERSION" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-version\fR - Bump a package version
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-view.1 b/deps/npm/man/man1/npm-view.1
index b9210c424cd..de67d3f900c 100644
--- a/deps/npm/man/man1/npm-view.1
+++ b/deps/npm/man/man1/npm-view.1
@@ -1,4 +1,4 @@
-.TH "NPM-VIEW" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-VIEW" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-view\fR - View registry info
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm-whoami.1 b/deps/npm/man/man1/npm-whoami.1
index 5d44c35a7f4..ddfde867876 100644
--- a/deps/npm/man/man1/npm-whoami.1
+++ b/deps/npm/man/man1/npm-whoami.1
@@ -1,4 +1,4 @@
-.TH "NPM-WHOAMI" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-WHOAMI" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-whoami\fR - Display npm username
.SS "Synopsis"
diff --git a/deps/npm/man/man1/npm.1 b/deps/npm/man/man1/npm.1
index 25a9e19288c..2f4b30a1f13 100644
--- a/deps/npm/man/man1/npm.1
+++ b/deps/npm/man/man1/npm.1
@@ -1,4 +1,4 @@
-.TH "NPM" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPM" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm\fR - javascript package manager
.SS "Synopsis"
@@ -12,7 +12,7 @@ npm
Note: This command is unaware of workspaces.
.SS "Version"
.P
-11.19.1
+11.20.0
.SS "Description"
.P
npm is the package manager for the Node JavaScript platform. It puts modules in place so that node can find them, and manages dependency conflicts intelligently.
diff --git a/deps/npm/man/man1/npx.1 b/deps/npm/man/man1/npx.1
index 39fcb358f7c..a50bf96cf46 100644
--- a/deps/npm/man/man1/npx.1
+++ b/deps/npm/man/man1/npx.1
@@ -1,4 +1,4 @@
-.TH "NPX" "1" "August 2026" "NPM@11.19.1" ""
+.TH "NPX" "1" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpx\fR - Run a command from a local or remote npm package
.SS "Synopsis"
diff --git a/deps/npm/man/man5/folders.5 b/deps/npm/man/man5/folders.5
index 7ec71429510..40aa02afd34 100644
--- a/deps/npm/man/man5/folders.5
+++ b/deps/npm/man/man5/folders.5
@@ -1,4 +1,4 @@
-.TH "FOLDERS" "5" "August 2026" "NPM@11.19.1" ""
+.TH "FOLDERS" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBFolders\fR - Folder structures used by npm
.SS "Description"
diff --git a/deps/npm/man/man5/install.5 b/deps/npm/man/man5/install.5
index b54f427c5da..af38748dc56 100644
--- a/deps/npm/man/man5/install.5
+++ b/deps/npm/man/man5/install.5
@@ -1,4 +1,4 @@
-.TH "INSTALL" "5" "August 2026" "NPM@11.19.1" ""
+.TH "INSTALL" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBInstall\fR - Download and install node and npm
.SS "Description"
diff --git a/deps/npm/man/man5/npm-global.5 b/deps/npm/man/man5/npm-global.5
index 7ec71429510..40aa02afd34 100644
--- a/deps/npm/man/man5/npm-global.5
+++ b/deps/npm/man/man5/npm-global.5
@@ -1,4 +1,4 @@
-.TH "FOLDERS" "5" "August 2026" "NPM@11.19.1" ""
+.TH "FOLDERS" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBFolders\fR - Folder structures used by npm
.SS "Description"
diff --git a/deps/npm/man/man5/npm-json.5 b/deps/npm/man/man5/npm-json.5
index 4a79f278885..41f16abf240 100644
--- a/deps/npm/man/man5/npm-json.5
+++ b/deps/npm/man/man5/npm-json.5
@@ -1,4 +1,4 @@
-.TH "PACKAGE.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "PACKAGE.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBpackage.json\fR - Specifics of npm's package.json handling
.SS "Description"
diff --git a/deps/npm/man/man5/npm-shrinkwrap-json.5 b/deps/npm/man/man5/npm-shrinkwrap-json.5
index 1af7bf467c0..ec1a2cdcfab 100644
--- a/deps/npm/man/man5/npm-shrinkwrap-json.5
+++ b/deps/npm/man/man5/npm-shrinkwrap-json.5
@@ -1,4 +1,4 @@
-.TH "NPM-SHRINKWRAP.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "NPM-SHRINKWRAP.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBnpm-shrinkwrap.json\fR - A publishable lockfile
.SS "Description"
diff --git a/deps/npm/man/man5/npmrc.5 b/deps/npm/man/man5/npmrc.5
index 9d236112608..d41c7e36a63 100644
--- a/deps/npm/man/man5/npmrc.5
+++ b/deps/npm/man/man5/npmrc.5
@@ -1,4 +1,4 @@
-.TH ".NPMRC" "5" "August 2026" "NPM@11.19.1" ""
+.TH ".NPMRC" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fB.npmrc\fR - The npm config files
.SS "Description"
diff --git a/deps/npm/man/man5/package-json.5 b/deps/npm/man/man5/package-json.5
index 4a79f278885..41f16abf240 100644
--- a/deps/npm/man/man5/package-json.5
+++ b/deps/npm/man/man5/package-json.5
@@ -1,4 +1,4 @@
-.TH "PACKAGE.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "PACKAGE.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBpackage.json\fR - Specifics of npm's package.json handling
.SS "Description"
diff --git a/deps/npm/man/man5/package-lock-json.5 b/deps/npm/man/man5/package-lock-json.5
index ace3d4d6959..46d19e3b57a 100644
--- a/deps/npm/man/man5/package-lock-json.5
+++ b/deps/npm/man/man5/package-lock-json.5
@@ -1,4 +1,4 @@
-.TH "PACKAGE-LOCK.JSON" "5" "August 2026" "NPM@11.19.1" ""
+.TH "PACKAGE-LOCK.JSON" "5" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBpackage-lock.json\fR - A manifestation of the manifest
.SS "Description"
diff --git a/deps/npm/man/man7/config.7 b/deps/npm/man/man7/config.7
index 684663e3375..92fba90eec0 100644
--- a/deps/npm/man/man7/config.7
+++ b/deps/npm/man/man7/config.7
@@ -1,4 +1,4 @@
-.TH "CONFIG" "7" "August 2026" "NPM@11.19.1" ""
+.TH "CONFIG" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBConfig\fR - About npm configuration
.SS "Description"
@@ -268,6 +268,8 @@ Comma-separated list of packages whose install-time lifecycle scripts (\fBpreins
This setting is intended for one-off and global contexts: \fBnpm exec\fR, \fBnpx\fR, and \fBnpm install -g\fR, where no project \fBpackage.json\fR is involved. For team-wide policy in a project, use the \fBallowScripts\fR field in \fBpackage.json\fR (which also supports explicit denials), or configure it in \fB.npmrc\fR. Passing \fB--allow-scripts\fR on the command line during a project-scoped \fBnpm install\fR, \fBci\fR, \fBupdate\fR, or \fBrebuild\fR is an error.
.P
Each name is matched against a dependency's resolved identity, not against the package's self-reported name. \fB--ignore-scripts\fR and \fB--dangerously-allow-all-scripts\fR both override this setting.
+.P
+This value is not exported to the environment for child processes.
.SS "\fBallow-scripts-pending\fR"
.RS 0
.IP \(bu 4
@@ -1429,11 +1431,11 @@ When creating a Granular Access Token with \fBnpm token create\fR, grants the to
.IP \(bu 4
Default: null
.IP \(bu 4
-Type: null, "read-only", "read-write", or "no-access"
+Type: null, "read-only", "read-write", "read-write-stage-only", or "no-access"
.RE 0
.P
-When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", or "no-access".
+When creating a Granular Access Token with \fBnpm token create\fR, sets the permission level for packages and scopes. Options are "read-only", "read-write", "read-write-stage-only", or "no-access". "read-write-stage-only" grants publish access that stages releases instead of publishing them directly.
.SS "\fBparseable\fR"
.RS 0
.IP \(bu 4
@@ -1527,6 +1529,8 @@ Type: Boolean
.P
When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from.
.P
+When the \fBprovenance-file\fR config is set, it takes precedence and automatic provenance generation (including via trusted publishing/OIDC) is skipped.
+.P
This config cannot be used with: \fBprovenance-file\fR
.SS "\fBprovenance-file\fR"
.RS 0
@@ -1539,6 +1543,8 @@ Type: Path
.P
When publishing, the provenance bundle at the given path will be used.
.P
+This takes precedence over automatic provenance generation in trusted publishing flows.
+.P
This config cannot be used with: \fBprovenance\fR
.SS "\fBproxy\fR"
.RS 0
diff --git a/deps/npm/man/man7/dependency-selectors.7 b/deps/npm/man/man7/dependency-selectors.7
index ec08ce0750b..c81faa51b8c 100644
--- a/deps/npm/man/man7/dependency-selectors.7
+++ b/deps/npm/man/man7/dependency-selectors.7
@@ -1,4 +1,4 @@
-.TH "SELECTORS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SELECTORS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBSelectors\fR - Dependency Selector Syntax & Querying
.SS "Description"
diff --git a/deps/npm/man/man7/developers.7 b/deps/npm/man/man7/developers.7
index aebb1f99a74..8d240d09d82 100644
--- a/deps/npm/man/man7/developers.7
+++ b/deps/npm/man/man7/developers.7
@@ -1,4 +1,4 @@
-.TH "DEVELOPERS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "DEVELOPERS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBDevelopers\fR - Developer guide
.SS "Description"
diff --git a/deps/npm/man/man7/logging.7 b/deps/npm/man/man7/logging.7
index 7fab6e08925..a0464b5231c 100644
--- a/deps/npm/man/man7/logging.7
+++ b/deps/npm/man/man7/logging.7
@@ -1,4 +1,4 @@
-.TH "LOGGING" "7" "August 2026" "NPM@11.19.1" ""
+.TH "LOGGING" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBLogging\fR - Why, What & How we Log
.SS "Description"
diff --git a/deps/npm/man/man7/orgs.7 b/deps/npm/man/man7/orgs.7
index 975eded22df..7c01081ea03 100644
--- a/deps/npm/man/man7/orgs.7
+++ b/deps/npm/man/man7/orgs.7
@@ -1,4 +1,4 @@
-.TH "ORGANIZATIONS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "ORGANIZATIONS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBOrganizations\fR - Working with teams & organizations
.SS "Description"
diff --git a/deps/npm/man/man7/package-spec.7 b/deps/npm/man/man7/package-spec.7
index a68e9b8f7e7..9261a4edc18 100644
--- a/deps/npm/man/man7/package-spec.7
+++ b/deps/npm/man/man7/package-spec.7
@@ -1,4 +1,4 @@
-.TH "SPEC" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SPEC" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBspec\fR - Package name specifier
.SS "Description"
diff --git a/deps/npm/man/man7/registry.7 b/deps/npm/man/man7/registry.7
index a91c60c1456..a529ad8c25d 100644
--- a/deps/npm/man/man7/registry.7
+++ b/deps/npm/man/man7/registry.7
@@ -1,4 +1,4 @@
-.TH "REGISTRY" "7" "August 2026" "NPM@11.19.1" ""
+.TH "REGISTRY" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBRegistry\fR - The JavaScript Package Registry
.SS "Description"
diff --git a/deps/npm/man/man7/removal.7 b/deps/npm/man/man7/removal.7
index bb4d7a8d436..de3d5663c0b 100644
--- a/deps/npm/man/man7/removal.7
+++ b/deps/npm/man/man7/removal.7
@@ -1,4 +1,4 @@
-.TH "REMOVAL" "7" "August 2026" "NPM@11.19.1" ""
+.TH "REMOVAL" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBRemoval\fR - Cleaning the slate
.SS "Synopsis"
diff --git a/deps/npm/man/man7/scope.7 b/deps/npm/man/man7/scope.7
index f2744feb134..37b246569f7 100644
--- a/deps/npm/man/man7/scope.7
+++ b/deps/npm/man/man7/scope.7
@@ -1,4 +1,4 @@
-.TH "SCOPE" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SCOPE" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBScope\fR - Scoped packages
.SS "Description"
diff --git a/deps/npm/man/man7/scripts.7 b/deps/npm/man/man7/scripts.7
index 4af3522042b..d49e9941ba4 100644
--- a/deps/npm/man/man7/scripts.7
+++ b/deps/npm/man/man7/scripts.7
@@ -1,4 +1,4 @@
-.TH "SCRIPTS" "7" "August 2026" "NPM@11.19.1" ""
+.TH "SCRIPTS" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBScripts\fR - How npm handles the "scripts" field
.SS "Description"
diff --git a/deps/npm/man/man7/workspaces.7 b/deps/npm/man/man7/workspaces.7
index b31d897d2f3..7e74e51a60e 100644
--- a/deps/npm/man/man7/workspaces.7
+++ b/deps/npm/man/man7/workspaces.7
@@ -1,4 +1,4 @@
-.TH "WORKSPACES" "7" "August 2026" "NPM@11.19.1" ""
+.TH "WORKSPACES" "7" "September 2026" "NPM@11.20.0" ""
.SH "NAME"
\fBWorkspaces\fR - Working with workspaces
.SS "Description"
diff --git a/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js b/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js
index 2f8ed83e115..7ff7a21cf9b 100644
--- a/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js
+++ b/deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.js
@@ -257,6 +257,22 @@ module.exports = cls => class IdealTreeBuilder extends cls {
this[_updateNames] = update.names
this[_updateAll] = update.all
+
+ // validates list of rm names, they must
+ // be dep names only, no semver ranges are supported
+ for (const name of options.rm || []) {
+ const spec = npa(name)
+ const validationError =
+ new TypeError(`Remove arguments must only contain package names, eg:
+ npm rm ${spec.name || ''}`)
+ validationError.code = 'ERMARGS'
+
+ // If they gave us anything other than a bare package name
+ if (spec.raw !== spec.name) {
+ throw validationError
+ }
+ }
+
// we prune by default unless explicitly set to boolean false
this.#prune = options.prune !== false
@@ -1473,6 +1489,16 @@ This is a one-time fix-up, please be patient...
if (!edge.to) {
if (!parentEdge) {
+ // the peer is missing from the virtual root; check the real tree before skipping.
+ // we can avoid a fetch for an optional peer, or a compatible provider, though
+ // an incompatible provider still has to be resolved here so that the
+ // optional peer set nests instead of displacing required peers.
+ if (edge.type === 'peerOptional') {
+ const current = node.parent.sourceReference.resolve(edge.name)
+ if (!current || current.satisfies(edge)) {
+ continue
+ }
+ }
// easy, just put the thing there
await this.#nodeFromEdge(edge, node.parent, null, required)
continue
diff --git a/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js b/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js
index 8c9b3fe118a..629625f8e4f 100644
--- a/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js
+++ b/deps/npm/node_modules/@npmcli/arborist/lib/script-allowed.js
@@ -71,7 +71,7 @@ const isScriptAllowed = (node, policy) => {
const matches = (node, key, failClosed) => {
let parsed
try {
- parsed = npa(key)
+ parsed = npa(key, node?.root?.path)
} catch {
return false
}
@@ -328,8 +328,15 @@ const matchGit = (node, parsed) => {
}
const matchFileOrDir = (node, parsed) => {
+ // consistentResolve stores local sources as `file:` plus npa's absolute,
+ // platform-native fetchSpec.
+ const absoluteFileSpec = parsed.fetchSpec && `file:${parsed.fetchSpec}`
return resolvedSourceSpecs(node)
- .some(resolved => resolved === parsed.saveSpec || resolved === parsed.fetchSpec)
+ .some(resolved =>
+ resolved === parsed.saveSpec ||
+ resolved === parsed.fetchSpec ||
+ resolved === absoluteFileSpec
+ )
}
const matchRemote = (node, parsed) => {
@@ -381,4 +388,5 @@ module.exports.matches = matches
module.exports.isExactVersionDisjunction = isExactVersionDisjunction
module.exports.getTrustedRegistryIdentity = getTrustedRegistryIdentity
module.exports.resolvedSourceSpecs = resolvedSourceSpecs
+module.exports.matchFileOrDir = matchFileOrDir
module.exports.trustedDisplay = trustedDisplay
diff --git a/deps/npm/node_modules/@npmcli/arborist/package.json b/deps/npm/node_modules/@npmcli/arborist/package.json
index 1b71dfa4f12..8bd0ffeaa94 100644
--- a/deps/npm/node_modules/@npmcli/arborist/package.json
+++ b/deps/npm/node_modules/@npmcli/arborist/package.json
@@ -1,6 +1,6 @@
{
"name": "@npmcli/arborist",
- "version": "9.9.1",
+ "version": "9.9.2",
"description": "Manage node_modules trees",
"dependencies": {
"@gar/promise-retry": "^1.0.0",
diff --git a/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js b/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js
index 2bb1713458a..28be4cbd587 100644
--- a/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js
+++ b/deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.js
@@ -258,6 +258,7 @@ const definitions = {
default: '',
type: [String, Array],
hint: '',
+ envExport: false,
description: `
Comma-separated list of packages whose install-time lifecycle scripts
(\`preinstall\`, \`install\`, \`postinstall\`, and \`prepare\` for
@@ -1880,6 +1881,10 @@ const definitions = {
description: `
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+
+ When the \`provenance-file\` config is set, it takes precedence and
+ automatic provenance generation (including via trusted publishing/OIDC)
+ is skipped.
`,
flatten,
}),
@@ -1890,6 +1895,9 @@ const definitions = {
exclusive: ['provenance'],
description: `
When publishing, the provenance bundle at the given path will be used.
+
+ This takes precedence over automatic provenance generation in trusted
+ publishing flows.
`,
flatten,
}),
@@ -2208,11 +2216,13 @@ const definitions = {
}),
'packages-and-scopes-permission': new Definition('packages-and-scopes-permission', {
default: null,
- type: [null, 'read-only', 'read-write', 'no-access'],
+ type: [null, 'read-only', 'read-write', 'read-write-stage-only', 'no-access'],
description: `
When creating a Granular Access Token with \`npm token create\`,
sets the permission level for packages and scopes. Options are
- "read-only", "read-write", or "no-access".
+ "read-only", "read-write", "read-write-stage-only", or "no-access".
+ "read-write-stage-only" grants publish access that stages releases
+ instead of publishing them directly.
`,
flatten,
}),
diff --git a/deps/npm/node_modules/@npmcli/config/package.json b/deps/npm/node_modules/@npmcli/config/package.json
index 360b0ab128a..dcc39cef2ac 100644
--- a/deps/npm/node_modules/@npmcli/config/package.json
+++ b/deps/npm/node_modules/@npmcli/config/package.json
@@ -1,6 +1,6 @@
{
"name": "@npmcli/config",
- "version": "10.12.0",
+ "version": "10.13.0",
"files": [
"bin/",
"lib/"
diff --git a/deps/npm/node_modules/libnpmdiff/package.json b/deps/npm/node_modules/libnpmdiff/package.json
index 8ce3729c325..f9836046f44 100644
--- a/deps/npm/node_modules/libnpmdiff/package.json
+++ b/deps/npm/node_modules/libnpmdiff/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmdiff",
- "version": "8.1.12",
+ "version": "8.1.13",
"description": "The registry diff",
"repository": {
"type": "git",
@@ -47,7 +47,7 @@
"tap": "^16.3.8"
},
"dependencies": {
- "@npmcli/arborist": "^9.9.1",
+ "@npmcli/arborist": "^9.9.2",
"@npmcli/installed-package-contents": "^4.0.0",
"binary-extensions": "^3.0.0",
"diff": "^8.0.2",
diff --git a/deps/npm/node_modules/libnpmexec/package.json b/deps/npm/node_modules/libnpmexec/package.json
index c76c285e56a..116a7194043 100644
--- a/deps/npm/node_modules/libnpmexec/package.json
+++ b/deps/npm/node_modules/libnpmexec/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmexec",
- "version": "10.3.2",
+ "version": "10.3.3",
"files": [
"bin/",
"lib/"
@@ -61,7 +61,7 @@
},
"dependencies": {
"@gar/promise-retry": "^1.0.0",
- "@npmcli/arborist": "^9.9.1",
+ "@npmcli/arborist": "^9.9.2",
"@npmcli/package-json": "^7.0.0",
"@npmcli/run-script": "^10.0.0",
"ci-info": "^4.0.0",
diff --git a/deps/npm/node_modules/libnpmfund/package.json b/deps/npm/node_modules/libnpmfund/package.json
index 88852421c70..dcae1eb7476 100644
--- a/deps/npm/node_modules/libnpmfund/package.json
+++ b/deps/npm/node_modules/libnpmfund/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmfund",
- "version": "7.0.26",
+ "version": "7.0.27",
"main": "lib/index.js",
"files": [
"bin/",
@@ -46,7 +46,7 @@
"tap": "^16.3.8"
},
"dependencies": {
- "@npmcli/arborist": "^9.9.1"
+ "@npmcli/arborist": "^9.9.2"
},
"engines": {
"node": "^20.17.0 || >=22.9.0"
diff --git a/deps/npm/node_modules/libnpmpack/package.json b/deps/npm/node_modules/libnpmpack/package.json
index 54c31fccd63..c4b3dc30d7e 100644
--- a/deps/npm/node_modules/libnpmpack/package.json
+++ b/deps/npm/node_modules/libnpmpack/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmpack",
- "version": "9.1.13",
+ "version": "9.1.14",
"description": "Programmatic API for the bits behind npm pack",
"author": "GitHub Inc.",
"main": "lib/index.js",
@@ -37,7 +37,7 @@
"bugs": "https://github.com/npm/libnpmpack/issues",
"homepage": "https://npmjs.com/package/libnpmpack",
"dependencies": {
- "@npmcli/arborist": "^9.9.1",
+ "@npmcli/arborist": "^9.9.2",
"@npmcli/run-script": "^10.0.0",
"npm-package-arg": "^13.0.0",
"pacote": "^21.0.2"
diff --git a/deps/npm/node_modules/libnpmpublish/README.md b/deps/npm/node_modules/libnpmpublish/README.md
index 4daac34feaa..3abc096f6d8 100644
--- a/deps/npm/node_modules/libnpmpublish/README.md
+++ b/deps/npm/node_modules/libnpmpublish/README.md
@@ -53,11 +53,15 @@ A couple of options of note:
* `opts.provenance` - when running in a supported CI environment, will trigger
the generation of a signed provenance statement to be published alongside
- the package. Mutually exclusive with the `provenanceFile` option.
+ the package. Mutually exclusive with the `provenanceFile` option; providing
+ both will throw an `EUSAGE` error. In the npm CLI's trusted
+ publishing flows, automatic provenance generation is skipped when
+ `provenanceFile` is supplied.
* `opts.provenanceFile` - specifies the path to an externally-generated
provenance statement to be published alongside the package. Mutually
- exclusive with the `provenance` option. The specified file should be a
+ exclusive with the `provenance` option; providing both will throw an
+ `EUSAGE` error. The specified file should be a
[Sigstore Bundle](https://github.com/sigstore/protobuf-specs/blob/main/protos/sigstore_bundle.proto)
containing a [DSSE](https://github.com/secure-systems-lab/dsse)-packaged
provenance statement.
diff --git a/deps/npm/node_modules/libnpmpublish/lib/publish.js b/deps/npm/node_modules/libnpmpublish/lib/publish.js
index cfe85d2d29f..2cfd5435729 100644
--- a/deps/npm/node_modules/libnpmpublish/lib/publish.js
+++ b/deps/npm/node_modules/libnpmpublish/lib/publish.js
@@ -134,6 +134,12 @@ const buildMetadata = async (registry, manifest, tarballData, spec, opts) => {
// Handle case where --provenance flag was set to true
let transparencyLogUrl
+ if (provenance === true && provenanceFile) {
+ throw Object.assign(
+ new Error('provenance and provenanceFile cannot be used together'),
+ { code: 'EUSAGE' }
+ )
+ }
if (provenance === true || provenanceFile) {
let provenanceBundle
const subject = {
diff --git a/deps/npm/node_modules/libnpmpublish/package.json b/deps/npm/node_modules/libnpmpublish/package.json
index 5b4ae66e572..5b0ea2d47d2 100644
--- a/deps/npm/node_modules/libnpmpublish/package.json
+++ b/deps/npm/node_modules/libnpmpublish/package.json
@@ -1,6 +1,6 @@
{
"name": "libnpmpublish",
- "version": "11.2.0",
+ "version": "11.2.1",
"description": "Programmatic API for the bits behind npm publish and unpublish",
"author": "GitHub Inc.",
"main": "lib/index.js",
diff --git a/deps/npm/package.json b/deps/npm/package.json
index a67f3456955..44b3ca52029 100644
--- a/deps/npm/package.json
+++ b/deps/npm/package.json
@@ -1,5 +1,5 @@
{
- "version": "11.19.1",
+ "version": "11.20.0",
"name": "npm",
"description": "a package manager for JavaScript",
"workspaces": [
@@ -52,8 +52,8 @@
},
"dependencies": {
"@isaacs/string-locale-compare": "^1.1.0",
- "@npmcli/arborist": "^9.9.1",
- "@npmcli/config": "^10.12.0",
+ "@npmcli/arborist": "^9.9.2",
+ "@npmcli/config": "^10.13.0",
"@npmcli/fs": "^5.0.0",
"@npmcli/map-workspaces": "^5.0.3",
"@npmcli/metavuln-calculator": "^9.0.3",
@@ -77,12 +77,12 @@
"is-cidr": "^6.0.4",
"json-parse-even-better-errors": "^5.0.0",
"libnpmaccess": "^10.0.3",
- "libnpmdiff": "^8.1.12",
- "libnpmexec": "^10.3.2",
- "libnpmfund": "^7.0.26",
+ "libnpmdiff": "^8.1.13",
+ "libnpmexec": "^10.3.3",
+ "libnpmfund": "^7.0.27",
"libnpmorg": "^8.0.1",
- "libnpmpack": "^9.1.13",
- "libnpmpublish": "^11.2.0",
+ "libnpmpack": "^9.1.14",
+ "libnpmpublish": "^11.2.1",
"libnpmsearch": "^9.0.1",
"libnpmteam": "^8.0.2",
"libnpmversion": "^8.0.4",
diff --git a/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs b/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs
index 1e2799652c9..25c42722d94 100644
--- a/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs
+++ b/deps/npm/tap-snapshots/test/lib/docs.js.test.cjs
@@ -327,7 +327,7 @@ Each name is matched against a dependency's resolved identity, not against
the package's self-reported name. \`--ignore-scripts\` and
\`--dangerously-allow-all-scripts\` both override this setting.
-
+This value is not exported to the environment for child processes.
#### \`allow-scripts-pending\`
@@ -1529,11 +1529,14 @@ token access to all packages instead of limiting to specific packages.
#### \`packages-and-scopes-permission\`
* Default: null
-* Type: null, "read-only", "read-write", or "no-access"
+* Type: null, "read-only", "read-write", "read-write-stage-only", or
+ "no-access"
When creating a Granular Access Token with \`npm token create\`, sets the
permission level for packages and scopes. Options are "read-only",
-"read-write", or "no-access".
+"read-write", "read-write-stage-only", or "no-access".
+"read-write-stage-only" grants publish access that stages releases instead
+of publishing them directly.
@@ -1631,6 +1634,9 @@ Set to \`false\` to suppress the progress bar.
When publishing from a supported cloud CI/CD system, the package will be
publicly linked to where it was built and published from.
+When the \`provenance-file\` config is set, it takes precedence and automatic
+provenance generation (including via trusted publishing/OIDC) is skipped.
+
This config cannot be used with: \`provenance-file\`
#### \`provenance-file\`
@@ -1640,6 +1646,9 @@ This config cannot be used with: \`provenance-file\`
When publishing, the provenance bundle at the given path will be used.
+This takes precedence over automatic provenance generation in trusted
+publishing flows.
+
This config cannot be used with: \`provenance\`
#### \`proxy\`
@@ -6334,7 +6343,7 @@ Options:
[--name ] [--token-description ] [--expires ]
[--packages [--packages ...]] [--packages-all]
[--scopes [--scopes ...]] [--orgs [--orgs ...]]
-[--packages-and-scopes-permission ]
+[--packages-and-scopes-permission ]
[--orgs-permission ]
[--cidr [--cidr ...]] [--bypass-2fa] [--password ]
[--registry ] [--otp ] [--read-only]
diff --git a/deps/npm/test/fixtures/mock-oidc.js b/deps/npm/test/fixtures/mock-oidc.js
index d15d52c1b81..e2e11b27224 100644
--- a/deps/npm/test/fixtures/mock-oidc.js
+++ b/deps/npm/test/fixtures/mock-oidc.js
@@ -101,7 +101,7 @@ const mockOidc = async (t, {
ciInfo.CIRCLE = CIRCLE
})
- const { npm, registry, joinedOutput, logs } = await loadNpmWithRegistry(t, {
+ const { npm, registry, joinedOutput, logs, prefix } = await loadNpmWithRegistry(t, {
config: {
loglevel: 'silly',
...config,
@@ -117,11 +117,12 @@ const mockOidc = async (t, {
})
if (mockGithubOidcOptions) {
- const { idToken, audience, statusCode = 200 } = mockGithubOidcOptions
+ const { idToken, audience, statusCode = 200, times = 1 } = mockGithubOidcOptions
const url = new URL(ACTIONS_ID_TOKEN_REQUEST_URL)
nock(url.origin)
.get(url.pathname)
.query({ audience })
+ .times(times)
.matchHeader('authorization', `Bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}`)
.matchHeader('accept', 'application/json')
.reply(statusCode, statusCode !== 500 ? { value: idToken } : { message: 'Internal Server Error' })
@@ -160,7 +161,7 @@ const mockOidc = async (t, {
})
}
- return { npm, joinedOutput, logs, ACTIONS_ID_TOKEN_REQUEST_URL }
+ return { npm, registry, prefix, joinedOutput, logs, ACTIONS_ID_TOKEN_REQUEST_URL }
}
const oidcPublishTest = (opts) => {
diff --git a/deps/npm/test/lib/commands/pack.js b/deps/npm/test/lib/commands/pack.js
index 21d961ebef6..6f1f4453e33 100644
--- a/deps/npm/test/lib/commands/pack.js
+++ b/deps/npm/test/lib/commands/pack.js
@@ -256,7 +256,7 @@ t.test('invalid packument', async t => {
})
t.test('workspaces', async t => {
- const loadWorkspaces = (t) => loadMockNpm(t, {
+ const loadWorkspaces = (t, config = { workspaces: true }) => loadMockNpm(t, {
prefixDir: {
'package.json': JSON.stringify(
{
@@ -281,7 +281,7 @@ t.test('workspaces', async t => {
},
},
config: {
- workspaces: true,
+ ...config,
// TODO: this is a workaround for npm run test-all
// somehow leaking include-workspace-root
'include-workspace-root': false,
@@ -301,8 +301,10 @@ t.test('workspaces', async t => {
})
t.test('one workspace', async t => {
- const { npm, outputs } = await loadWorkspaces(t)
- await npm.exec('pack', ['workspace-a'])
+ const { npm, outputs } = await loadWorkspaces(t, {
+ workspace: ['workspace-a'],
+ })
+ await npm.exec('pack', [])
t.strictSame(outputs, ['workspace-a-1.0.0.tgz'])
})
diff --git a/deps/npm/test/lib/commands/publish.js b/deps/npm/test/lib/commands/publish.js
index 98576b08ea3..8b20c5671aa 100644
--- a/deps/npm/test/lib/commands/publish.js
+++ b/deps/npm/test/lib/commands/publish.js
@@ -3,6 +3,8 @@ const { loadNpmWithRegistry } = require('../../fixtures/mock-npm')
const { cleanZlib } = require('../../fixtures/clean-snapshot')
const pacote = require('pacote')
const Arborist = require('@npmcli/arborist')
+const npa = require('npm-package-arg')
+const ssri = require('ssri')
const path = require('node:path')
const fs = require('node:fs')
const { circleciIdToken, githubIdToken, gitlabIdToken, oidcPublishTest, mockOidc } = require('../../fixtures/mock-oidc')
@@ -1495,6 +1497,256 @@ t.test('oidc token exchange - provenance', (t) => {
},
}))
+ const provenanceFileSources = [
+ {
+ name: 'CLI config',
+ options: provenanceBundlePath => ({
+ config: {
+ 'provenance-file': provenanceBundlePath,
+ },
+ }),
+ },
+ {
+ // exercises Publish.#getManifest() and its flatten(filteredPublishConfig, opts)
+ // path: publishConfig must reach opts.provenanceFile before oidc() decides
+ // whether to enable automatic provenance
+ name: 'publishConfig',
+ options: provenanceBundlePath => ({
+ packageJson: {
+ publishConfig: {
+ 'provenance-file': provenanceBundlePath,
+ },
+ },
+ }),
+ },
+ ]
+
+ for (const { name, options } of provenanceFileSources) {
+ t.test(`${name} provenance-file takes precedence over OIDC auto-provenance`, async t => {
+ const bundleDir = t.testdir()
+ const provenanceBundlePath = path.join(
+ bundleDir,
+ 'provenance-bundle.json'
+ )
+ // holder so the libnpmpack mock can return the tarball computed below
+ const packMock = { tarballData: null }
+
+ const sourceOptions = options(provenanceBundlePath)
+
+ const { npm, registry, prefix, joinedOutput } = await mockOidc(t, {
+ oidcOptions: { github: true },
+ config: {
+ '//registry.npmjs.org/:_authToken': 'existing-fallback-token',
+ ...sourceOptions.config,
+ },
+ packageJson: sourceOptions.packageJson,
+ mockGithubOidcOptions: {
+ audience: 'npm:registry.npmjs.org',
+ idToken: githubPublicIdToken,
+ },
+ mockOidcTokenExchangeOptions: {
+ idToken: githubPublicIdToken,
+ body: {
+ token: 'exchange-token',
+ },
+ },
+ publishOptions: {
+ token: 'exchange-token',
+ noPut: true,
+ },
+ load: {
+ mocks: {
+ libnpmaccess: {
+ getVisibility: async () => ({ public: true }),
+ },
+ // publish a deterministic tarball so the bundle subject digest can match it
+ libnpmpack: async () => packMock.tarballData,
+ // libnpmpublish must be mocked as a module so its internal require of
+ // sigstore is intercepted: a user-supplied bundle is only verified,
+ // generation (attest) must never run
+ libnpmpublish: t.mock('libnpmpublish', {
+ 'libnpmpublish/lib/provenance': t.mock('libnpmpublish/lib/provenance', {
+ sigstore: {
+ verify: async () => {},
+ attest: async () => {
+ throw new Error('sigstore.attest must not be called when provenance-file is configured')
+ },
+ },
+ }),
+ }),
+ },
+ },
+ })
+
+ // compute the tarball integrity the same way libnpmpublish does so the
+ // provenance bundle subject matches the packed tarball
+ packMock.tarballData = await pacote.tarball(prefix, { Arborist })
+ const integrity = ssri.fromData(packMock.tarballData, { algorithms: ['sha512'] })
+ const spec = npa.resolve(pkg, '1.0.0')
+ const provenanceBundle = {
+ mediaType: 'application/vnd.dev.sigstore.bundle+json;version=0.2',
+ verificationMaterial: {
+ x509CertificateChain: {
+ certificates: [{ rawBytes: 'dGVzdA==' }],
+ },
+ tlogEntries: [],
+ },
+ dsseEnvelope: {
+ payload: Buffer.from(JSON.stringify({
+ _type: 'https://in-toto.io/Statement/v0.1',
+ subject: [
+ {
+ name: npa.toPurl(spec),
+ digest: { sha512: integrity.sha512[0].hexDigest() },
+ },
+ ],
+ predicateType: 'https://slsa.dev/provenance/v0.2',
+ predicate: {},
+ })).toString('base64'),
+ payloadType: 'application/vnd.in-toto+json',
+ signatures: [{
+ /* eslint-disable-next-line max-len */
+ sig: 'MEUCIQDqHtpkk1d0rMGLmf3qet9jLale3KVn8Pnywpwt7ln+9AIgG9CJvvUmyemhNYHz0DfJ4vMfKk1TMg+m3hR0mISXJos=',
+ keyid: '',
+ }],
+ },
+ }
+ fs.writeFileSync(provenanceBundlePath, JSON.stringify(provenanceBundle, null, 2))
+
+ let publishedBody
+ registry.nock
+ .put(`/${spec.escapedName}`, (body) => {
+ publishedBody = body
+ return true
+ })
+ .matchHeader('authorization', 'Bearer exchange-token')
+ // optional so a failed publish does not leave a pending mock behind
+ .optionally()
+ .reply(200, {})
+
+ // libnpmpublish checks package visibility itself before generating
+ // provenance; optional so it is only consumed if generation is attempted
+ registry.nock
+ .get(`/-/package/${spec.escapedName}/visibility`)
+ .optionally()
+ .reply(200, { public: true })
+
+ await npm.exec('publish', [])
+
+ t.match(joinedOutput(), '+ @npmcli/test-package@1.0.0')
+
+ const attachment =
+ publishedBody?._attachments[`${pkg}-1.0.0.sigstore`]
+
+ t.ok(attachment, 'published packument includes supplied provenance')
+ t.strictSame(
+ JSON.parse(attachment.data),
+ provenanceBundle,
+ 'published sigstore bundle is the user-supplied provenance file'
+ )
+ })
+ }
+
+ t.test('automatic provenance does not leak between workspace publishes', async t => {
+ const provenanceBundlePath = path.join(t.testdir(), 'provenance-bundle.json')
+ const autoPackage = 'workspace-auto-provenance'
+ const filePackage = 'workspace-file-provenance'
+ const publishCalls = []
+ const prefixDir = {
+ 'package.json': JSON.stringify({
+ name: 'workspace-root',
+ version: '1.0.0',
+ workspaces: [autoPackage, filePackage],
+ }),
+ [autoPackage]: {
+ 'package.json': JSON.stringify({
+ name: autoPackage,
+ version: '1.0.0',
+ }),
+ },
+ [filePackage]: {
+ 'package.json': JSON.stringify({
+ name: filePackage,
+ version: '1.0.0',
+ publishConfig: {
+ 'provenance-file': provenanceBundlePath,
+ },
+ }),
+ },
+ }
+
+ const { npm, registry } = await mockOidc(t, {
+ oidcOptions: { github: true },
+ packageName: autoPackage,
+ config: {
+ '//registry.npmjs.org/:_authToken': 'existing-fallback-token',
+ workspaces: true,
+ },
+ mockGithubOidcOptions: {
+ audience: 'npm:registry.npmjs.org',
+ idToken: githubPublicIdToken,
+ times: 2,
+ },
+ mockOidcTokenExchangeOptions: {
+ idToken: githubPublicIdToken,
+ body: {
+ token: 'exchange-token',
+ },
+ },
+ publishOptions: {
+ noPut: true,
+ },
+ load: {
+ prefixDir,
+ mocks: {
+ libnpmaccess: {
+ getVisibility: async () => ({ public: true }),
+ },
+ // mocked as a plain module so the publish options each workspace
+ // receives can be recorded verbatim
+ libnpmpublish: {
+ publish: async (manifest, _tarballData, opts) => {
+ publishCalls.push({
+ name: manifest.name,
+ provenance: opts.provenance,
+ provenanceFile: opts.provenanceFile,
+ })
+ },
+ },
+ },
+ },
+ })
+
+ registry.mockOidcTokenExchange({
+ packageName: filePackage,
+ idToken: githubPublicIdToken,
+ body: {
+ token: 'exchange-token',
+ },
+ })
+ registry.publish(filePackage, { noPut: true })
+
+ await npm.exec('publish', [])
+
+ t.strictSame(publishCalls, [
+ {
+ name: autoPackage,
+ provenance: true,
+ provenanceFile: null,
+ },
+ {
+ name: filePackage,
+ provenance: false,
+ provenanceFile: provenanceBundlePath,
+ },
+ ])
+ t.equal(
+ npm.config.isDefault('provenance'),
+ true,
+ 'automatic provenance does not mutate shared config'
+ )
+ })
+
const brokenJwts = [
'x.invalid-jwt.x',
'x.invalid-jwt.',
diff --git a/deps/npm/test/lib/commands/stage/list.js b/deps/npm/test/lib/commands/stage/list.js
index e66680db827..ded079a5ab7 100644
--- a/deps/npm/test/lib/commands/stage/list.js
+++ b/deps/npm/test/lib/commands/stage/list.js
@@ -15,6 +15,7 @@ const stageItems = [
actor: 'octocat',
actorType: 'user',
shasum: '4f7f5f1d5bcf2f72f6e4d6c4f3b2812d8a2f6c19',
+ status: 'validating',
},
{
id: 'f8e7a45b-7a5f-4f31-8e6d-9dd1c6ef38c0',
@@ -25,6 +26,7 @@ const stageItems = [
actor: 'npm-bot',
actorType: 'trusted automation',
shasum: '8eb3b4e9b6e3d0d2c86be1e6d4f43f4be62e80ad',
+ status: 'staged',
},
]
@@ -45,6 +47,9 @@ t.test('lists all staged packages', async t => {
t.match(out, 'package name: example-lib')
t.match(out, 'version: 1.2.3')
t.match(out, 'version: 0.4.0')
+ t.match(out, 'status: validating')
+ t.match(out, 'status: staged')
+ t.equal(out.match(/status:/g)?.length, 2, 'all server-provided statuses are shown')
})
t.test('lists with package filter', async t => {
@@ -80,6 +85,8 @@ t.test('lists with --json', async t => {
t.equal(out.length, 2)
t.equal(out[0].packageName, '@npmcli/example-package')
t.equal(out[0].id, '1de6f3db-2ed9-4d72-b3dd-8f0e2b474a2f', 'uuid id is not redacted')
+ t.equal(out[0].status, 'validating')
+ t.equal(out[1].status, 'staged')
})
t.test('shows message when no packages', async t => {
diff --git a/deps/npm/test/lib/commands/stage/view.js b/deps/npm/test/lib/commands/stage/view.js
index 604caf98fb2..36afc98b13d 100644
--- a/deps/npm/test/lib/commands/stage/view.js
+++ b/deps/npm/test/lib/commands/stage/view.js
@@ -14,6 +14,7 @@ const stageItem = {
actor: 'octocat',
actorType: 'user',
shasum: '4f7f5f1d5bcf2f72f6e4d6c4f3b2812d8a2f6c19',
+ status: 'awaiting_approval',
}
t.test('views a staged package', async t => {
@@ -31,6 +32,7 @@ t.test('views a staged package', async t => {
t.match(out, /id:/)
t.match(out, 'package name: @npmcli/example-package')
t.match(out, 'version: 1.2.3')
+ t.match(out, 'status: awaiting_approval')
})
t.test('views with --json', async t => {
@@ -47,6 +49,7 @@ t.test('views with --json', async t => {
const out = JSON.parse(joinedOutput())
t.ok(out.id)
t.equal(out.packageName, '@npmcli/example-package')
+ t.equal(out.status, 'awaiting_approval')
})
t.test('throws usageError without stage-id', async t => {
diff --git a/deps/npm/test/lib/commands/token.js b/deps/npm/test/lib/commands/token.js
index 34297a923c8..41ca9395375 100644
--- a/deps/npm/test/lib/commands/token.js
+++ b/deps/npm/test/lib/commands/token.js
@@ -475,3 +475,115 @@ t.test('token create invalid cidr', async t => {
message: 'CIDR whitelist contains invalid CIDR entry: apple/cider',
})
})
+
+t.test('token create stage-only produces stage-only policy and no warning', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'stage-only-token',
+ password: 'test-password',
+ 'packages-and-scopes-permission': 'read-write-stage-only',
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'stage-only-token',
+ password: 'test-password',
+ packages_and_scopes_permission: 'read-write-stage-only',
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.strictSame(logs.warn, [], 'no deprecation warning for stage-only tokens')
+})
+
+t.test('token create read-write warns about direct-publish', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'rw-token',
+ password: 'test-password',
+ 'packages-and-scopes-permission': 'read-write',
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'rw-token',
+ password: 'test-password',
+ packages_and_scopes_permission: 'read-write',
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.match(logs.warn, [/publish directly to the registry/], 'warns about direct-publish token')
+ t.match(logs.warn, [/read-write-stage-only/], 'warning points to stage-only tokens')
+ t.match(logs.warn, [/https:\/\/gh\.io\/bypass-2fa-tokens-no-longer-publish/], 'warning includes the docs link')
+})
+
+t.test('token create bypass-2fa alone does not warn', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'bypass-token',
+ password: 'test-password',
+ 'bypass-2fa': true,
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'bypass-token',
+ password: 'test-password',
+ bypass_2fa: true,
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.strictSame(logs.warn, [], 'bypass-2fa alone grants no publish capability, so no warning')
+})
+
+t.test('token create read-write with bypass-2fa warns about direct-publish', async t => {
+ const { npm, outputs, logs } = await loadMockNpm(t, {
+ config: {
+ ...auth,
+ name: 'rw-bypass-token',
+ password: 'test-password',
+ 'packages-and-scopes-permission': 'read-write',
+ 'bypass-2fa': true,
+ },
+ })
+
+ const registry = new MockRegistry({
+ tap: t,
+ registry: npm.config.get('registry'),
+ authorization: authToken,
+ })
+
+ registry.createToken({
+ name: 'rw-bypass-token',
+ password: 'test-password',
+ packages_and_scopes_permission: 'read-write',
+ bypass_2fa: true,
+ })
+
+ await npm.exec('token', ['create'])
+ t.match(outputs, ['Created token n3wt0k3n'])
+ t.match(logs.warn, [/publish directly to the registry/], 'warns for read-write automation publish token')
+})
diff --git a/deps/npm/test/lib/commands/uninstall.js b/deps/npm/test/lib/commands/uninstall.js
index 049bf2da8b1..0302aa5bac3 100644
--- a/deps/npm/test/lib/commands/uninstall.js
+++ b/deps/npm/test/lib/commands/uninstall.js
@@ -143,6 +143,34 @@ t.test('remove multiple installed libs', async t => {
t.throws(() => fs.statSync(b), 'should have removed b package from nm')
})
+t.test('rejects an arg with a version spec', async t => {
+ const { uninstall } = await mockNpm(t, {
+ prefixDir: {
+ 'package.json': JSON.stringify({
+ name: 'test-rm-version-spec',
+ version: '1.0.0',
+ dependencies: {
+ foo: '*',
+ },
+ }),
+ node_modules: {
+ foo: {
+ 'package.json': JSON.stringify({
+ name: 'foo',
+ version: '1.0.0',
+ }),
+ },
+ },
+ },
+ })
+
+ await t.rejects(
+ uninstall(['foo@1']),
+ { code: 'ERMARGS', message: /npm rm foo/ },
+ 'should throw ERMARGS instead of silently no-oping'
+ )
+})
+
t.test('no args local', async t => {
const { uninstall } = await mockNpm(t)
diff --git a/deps/npm/test/lib/utils/allow-scripts-prune.js b/deps/npm/test/lib/utils/allow-scripts-prune.js
index 880b1dfe343..ea39bc6ecff 100644
--- a/deps/npm/test/lib/utils/allow-scripts-prune.js
+++ b/deps/npm/test/lib/utils/allow-scripts-prune.js
@@ -1,4 +1,5 @@
const t = require('tap')
+const path = require('node:path')
const { classifyUnusedEntries } = require('../../../lib/utils/allow-scripts-prune.js')
// Minimal registry node: `matches` derives name/version from the resolved URL.
@@ -29,6 +30,26 @@ t.test('keeps entries that match an installed package with scripts', t => {
t.end()
})
+t.test('keeps a local file key matching its absolute resolved source', t => {
+ const rootPath = path.resolve('project')
+ const key = `file:${path.resolve(rootPath, 'local.tgz')}`
+ const local = {
+ name: 'local',
+ version: '1.0.0',
+ resolved: key,
+ root: { path: rootPath },
+ isRegistryDependency: false,
+ }
+ const { remaining, removed } = classifyUnusedEntries(
+ { [key]: true },
+ [{ node: local, hasScripts: true }]
+ )
+
+ t.same(remaining, { [key]: true })
+ t.same(removed, [])
+ t.end()
+})
+
t.test('removes entries for packages no longer installed', t => {
const { remaining, removed } = classifyUnusedEntries(
{ canvas: true, gone: true },
diff --git a/deps/npm/test/lib/utils/allow-scripts-writer.js b/deps/npm/test/lib/utils/allow-scripts-writer.js
index 8edf25be307..f13389c8c25 100644
--- a/deps/npm/test/lib/utils/allow-scripts-writer.js
+++ b/deps/npm/test/lib/utils/allow-scripts-writer.js
@@ -1,8 +1,10 @@
const t = require('tap')
const path = require('node:path')
+const isScriptAllowed = require('../../../workspaces/arborist/lib/script-allowed.js')
const {
applyApprovalForPackage,
applyDenyForPackage,
+ keyTargetsNode,
nameKeyFor,
versionedKeyFor,
isSingleVersionPin,
@@ -379,6 +381,21 @@ t.test('applyApprovalForPackage — file dep uses resolved as both keys', async
t.strictSame(allowScripts, { 'file:../local': true })
})
+t.test('versionedKeyFor — local file key round-trips through policy matching', async t => {
+ const rootPath = path.resolve('project')
+ const local = {
+ name: 'local',
+ packageName: 'local',
+ version: '1.0.0',
+ resolved: `file:${path.resolve(rootPath, 'local.tgz')}`,
+ root: { path: rootPath },
+ isRegistryDependency: false,
+ }
+ const key = versionedKeyFor(local)
+
+ t.equal(isScriptAllowed(local, { [key]: true }), true)
+})
+
t.test('applyApprovalForPackage — empty nodes returns unchanged', async t => {
const { allowScripts, changes } = applyApprovalForPackage({ x: true }, [], { pin: true })
t.strictSame(allowScripts, { x: true })
@@ -493,6 +510,29 @@ t.test('applyApprovalForPackage — file dep with deny entry blocks approval', a
t.match(warning, /denied|versioned deny/)
})
+t.test('applyApprovalForPackage — relative file deny matches absolute resolved', async t => {
+ const rootPath = path.resolve('project')
+ const resolved = `file:${path.resolve(rootPath, 'local.tgz')}`
+ const local = {
+ name: 'local',
+ packageName: 'local',
+ version: '1.0.0',
+ resolved,
+ root: { path: rootPath },
+ isRegistryDependency: false,
+ }
+ const existing = { 'file:local.tgz': false }
+ const { allowScripts, changes, warning } = applyApprovalForPackage(
+ existing,
+ [local],
+ { pin: true }
+ )
+
+ t.strictSame(allowScripts, existing)
+ t.strictSame(changes, [])
+ t.match(warning, /denied|versioned deny/)
+})
+
t.test('applyApprovalForPackage — remote tarball deny blocks approval', async t => {
const remote = { name: 'pkg', packageName: 'pkg', version: '1.0.0', resolved: 'https://example.com/pkg.tgz' }
const { warning } = applyApprovalForPackage(
@@ -501,6 +541,7 @@ t.test('applyApprovalForPackage — remote tarball deny blocks approval', async
{ pin: true }
)
t.match(warning, /denied|versioned deny/)
+ t.equal(keyTargetsNode('https://example.com/other.tgz', remote), false)
})
t.test('applyApprovalForPackage — no-pin with no name produces no-op', async t => {
diff --git a/deps/npm/test/lib/utils/key-values.js b/deps/npm/test/lib/utils/key-values.js
index 5e61f9e55fe..f162346eab4 100644
--- a/deps/npm/test/lib/utils/key-values.js
+++ b/deps/npm/test/lib/utils/key-values.js
@@ -76,6 +76,40 @@ t.test('logStageItem without actorType shows actor alone', async t => {
t.notMatch(out, /\(/)
})
+t.test('logStageItem shows status returned by the server', async t => {
+ const { joinedOutput } = await loadMockNpm(t)
+ const chalk = { cyan: v => v, green: v => v }
+ const item = {
+ id: 'abc',
+ packageName: 'pkg',
+ version: '1.0.0',
+ tag: 'latest',
+ createdAt: '2026-01-01',
+ actor: 'user',
+ shasum: 'sha1',
+ }
+
+ logStageItem({ ...item, status: 'awaiting_approval' }, { chalk })
+ t.match(joinedOutput(), /status: awaiting_approval/)
+})
+
+t.test('logStageItem omits missing status', async t => {
+ const { joinedOutput } = await loadMockNpm(t)
+ const chalk = { cyan: v => v, green: v => v }
+ const item = {
+ id: 'abc',
+ packageName: 'pkg',
+ version: '1.0.0',
+ tag: 'latest',
+ createdAt: '2026-01-01',
+ actor: 'user',
+ shasum: 'sha1',
+ }
+
+ logStageItem(item, { chalk })
+ t.notMatch(joinedOutput(), /status:/)
+})
+
t.test('logObject with all values skipped produces no output', async t => {
const { joinedOutput } = await loadMockNpm(t)
const chalk = { cyan: v => v, green: v => v }
diff --git a/deps/npm/test/lib/utils/reify-output.js b/deps/npm/test/lib/utils/reify-output.js
index ee9201482a7..17939c712af 100644
--- a/deps/npm/test/lib/utils/reify-output.js
+++ b/deps/npm/test/lib/utils/reify-output.js
@@ -128,6 +128,35 @@ t.test('no message when funding config is false', async t => {
t.notMatch(out, 'looking for funding', 'should not print funding info')
})
+t.test('no message when installing globally', async t => {
+ const out = await mockReify(t, {
+ actualTree: {
+ name: 'foo',
+ package: {
+ name: 'foo',
+ version: '1.0.0',
+ },
+ edgesOut: new Map([
+ ['bar', {
+ to: {
+ name: 'bar',
+ package: {
+ name: 'bar',
+ version: '1.0.0',
+ funding: { type: 'foo', url: 'http://example.com' },
+ },
+ },
+ }],
+ ]),
+ },
+ diff: {
+ children: [],
+ },
+ }, { global: true })
+
+ t.notMatch(out, 'looking for funding', 'should not print funding info')
+})
+
t.test('print appropriate message for many packages', async t => {
const out = await mockReify(t, {
actualTree: {
@@ -440,6 +469,53 @@ t.test('prints dedupe difference on dry-run', async t => {
t.matchSnapshot(out, 'diff table')
})
+t.test('prints only json for dry-run and long', async t => {
+ for (const flag of ['dry-run', 'long']) {
+ await t.test(flag, async t => {
+ const out = await mockReify(t, {
+ actualTree: {
+ inventory: {
+ has: () => true,
+ },
+ children: [],
+ },
+ diff: {
+ children: [
+ {
+ action: 'ADD',
+ ideal: {
+ path: 'test/foo',
+ name: 'foo',
+ package: { version: '1.0.0' },
+ },
+ },
+ ],
+ },
+ }, {
+ [flag]: true,
+ json: true,
+ })
+
+ t.strictSame(JSON.parse(out), {
+ add: [
+ {
+ name: 'foo',
+ version: '1.0.0',
+ path: 'test/foo',
+ },
+ ],
+ added: 1,
+ audited: 0,
+ change: [],
+ changed: 0,
+ funding: 0,
+ remove: [],
+ removed: 0,
+ })
+ })
+ }
+})
+
t.test('prints dedupe difference on long', async t => {
const mock = {
actualTree: {
diff --git a/deps/npm/test/lib/utils/resolve-allow-scripts.js b/deps/npm/test/lib/utils/resolve-allow-scripts.js
index a27d600d98f..650094ba170 100644
--- a/deps/npm/test/lib/utils/resolve-allow-scripts.js
+++ b/deps/npm/test/lib/utils/resolve-allow-scripts.js
@@ -86,6 +86,22 @@ t.test('--allow-scripts CLI flag is rejected in project-scoped installs', async
)
})
+t.test('allow-scripts environment policy is rejected in project-scoped installs', async t => {
+ const mock = await mockNpm(t, {
+ prefixDir: {
+ 'package.json': JSON.stringify({ name: 'p' }),
+ },
+ globals: {
+ 'process.env.npm_config_allow_scripts': 'canvas',
+ },
+ })
+ const resolveAllowScripts = loadResolver(t)
+ await t.rejects(
+ resolveAllowScripts(mock.npm),
+ { code: 'EALLOWSCRIPTS', message: /--allow-scripts is not allowed/ }
+ )
+})
+
t.test('--allow-scripts CLI flag is accepted in global installs (RFC layer 1 wins)', async t => {
const mock = await mockNpm(t, {
prefixDir: {