Skip to content

fix: report signature checks skipped without registry keys - #10048

Open
greenlincoln05 wants to merge 2 commits into
npm:latestfrom
greenlincoln05:codex/audit-signature-coverage
Open

greenlincoln05 wants to merge 2 commits into
npm:latestfrom
greenlincoln05:codex/audit-signature-coverage

Conversation

@greenlincoln05

@greenlincoln05 greenlincoln05 commented Sep 27, 2026 •

Copy link
Copy Markdown

npm audit signatures can exit successfully after checking packages from registries with signing keys while silently omitting packages from registries without keys. In a mixed tree, it now reports the skipped count by registry host in the text summary and a skipped array with --json. The existing exit status and the error when no packages can be audited stay the same.

The reported registry origin omits URL paths and credentials. The key-fallback warning uses the same safe origin, so a registry URL containing a credential in its path is not echoed into audit output or logs.

Fixes #10018

Validation:

  • Targeted test/lib/commands/audit.js suite passed, including the credential-bearing registry regression (using a test-only compatibility preload for this host's cached dependency tree).
  • ESLint passed for the changed JavaScript files.
  • git diff --check passed.

@greenlincoln05
greenlincoln05 marked this pull request as ready for review September 27, 2026 23:14
@greenlincoln05
greenlincoln05 requested a review from a team as a code owner September 27, 2026 23:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

npm audit signatures does not report how many packages it skipped for want of registry keys

1 participant