Commit 7ab1f8f
committed
chore: upgrade to NPM v12
Require npm >=12.0.2 <13, enforced via check-node-version on npm install and
npm ci. CI installs the version from engines.npm via the new
.github/actions/install-npm composite action.
The motivation is that npm v12 turns three code-execution paths off by
default, most notably the unauthorized execution of install scripts:
- allowScripts now defaults to off, so npm install no longer executes
preinstall, install or postinstall scripts from dependencies unless they
are explicitly allowed in package.json. This also covers prepare scripts
from git, file and link dependencies.
- --allow-git now defaults to none, which closes a code-execution path where
a git dependency's .npmrc could override the git executable, even with
--ignore-scripts.
- --allow-remote now defaults to none, blocking dependencies from remote
URLs such as HTTPS tarballs.
See
https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
The check is skipped during npm publish and npm pack, because
semantic-release bundles its own npm (@semantic-release/npm depends on
npm@^11.6.2) and runs the publish with that version rather than the one
installed in CI.
The Node.js requirement is left unchanged.1 parent 6f19f57 commit 7ab1f8f
5 files changed
Lines changed: 210 additions & 1 deletion
File tree
- .github
- actions/install-npm
- workflows
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
25 | 28 | | |
26 | 29 | | |
27 | 30 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
| 16 | + | |
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| 23 | + | |
22 | 24 | | |
23 | 25 | | |
24 | 26 | | |
| |||
33 | 35 | | |
34 | 36 | | |
35 | 37 | | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
36 | 41 | | |
37 | 42 | | |
0 commit comments