NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4017 most downloaded on npm
Manage node_modules trees
Last release 12 days ago
22 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Most releases are documented
notes for 46 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
235 releases · first in 2020
One column per quarter.
71915e8 #9756 exempt explicit pack targets from allow-directory ( #9756 ) ( @ychampion , @ychampion )
71915e8 #9756 exempt explicit pack targets from allow-directory (#9756) (@ychampion, @ychampion)@npmcli/arborist@10.0.3`74eff59` #9770 arborist: avoid crash when peer back-off detaches a node (#9770) (@manzoorwanijk)
`47fc8b1` #9740 correct bundled sigstore from dev dependency conflict (#9740) (@james-pre)
npm shrinkwrap is removed, the shrinkwrap config alias is removed, and npm-shrinkwrap.json is no longer loaded or honored at the project root or from
npm shrinkwrap is removed, the shrinkwrap config alias is removed, and npm-shrinkwrap.json is no longer loaded or honored at the project root or from inside dependency tarballs. Rename project-root npm-shrinkwrap.json to package-lock.json; use bundleDependencies if you need to ship a locked dependency tree.npm now supports node ^22.22.2 || ^24.15.0 || >=26.0.0`b51d156` #9672 arborist: extend replace-registry-host with URL prefix matching (#6110) (#9672) (@u2mejc)
b51d156 #9672 arborist: extend replace-registry-host with URL prefix matching (#6110) (#9672) (@u2mejc)86416a6 #9674 graduate the linked install strategy from experimental to stable (#9674) (@manzoorwanijk)c4e5356 #9651 install-scripts: prune unused allowScripts entries (#9651) (@JamieMagee)58cd8f5 #9586 .npm-extension transformManifest for imperative manifest repairs (#9586) (@manzoorwanijk)968e42f #9671 arborist: apply overrides across a file:/workspace link boundary (#9671) (@manzoorwanijk)ae6dbeb #9657 arborist: surface undeclared workspaces under the linked strategy (#9657) (@manzoorwanijk)541c286 #9658 arborist: forward transitive overrides through linked store links (#9658) (@manzoorwanijk)f9e3a80 #9655 arborist: correct dev/prod dep flags for workspaces under the linked strategy (#9655) (@manzoorwanijk)6a5bf26 #9654 arborist: load transitive optional deps into linked actual tree (#9654) (@manzoorwanijk)803ba70 #9656 query: report logical dep location under linked strategy (#9656) (@manzoorwanijk)60d0d3d #9652 allowScripts: close three enforcement gaps (#9652) (@JamieMagee)ca92323 #9647 arborist: clean up stale .store and hoisted dirs on strategy switch (#9647) (@manzoorwanijk)2b976b5 #9637 arborist: invalid filterNode crash under the linked strategy (#9637) (@manzoorwanijk)0ffce98 #9628 arborist: repair wrong-but-existing symlink target in linked strategy (#9628) (@manzoorwanijk)981e249 #9632 arborist: remove stale .bin shims after uninstall under linked (#9632) (@manzoorwanijk)6968015 #9630 arborist: record the linked .store layout in the hidden lockfile (#9630) (@manzoorwanijk)2aa1c7c #9605 arborist: validate peerOptional conflicts in no-save mutations (#9605) (@dale-lakes, @dale-lakes)690bf17 #9603 arborist: fix audit-report determinism due to dropped via links (#9603) (@arjun-vegeta)851558c #9626 arborist: don't load store packages' devDependencies as required edges (#9626) (@manzoorwanijk)989f571 #9625 arborist: audit the non-isolated tree under the linked strategy (#9625) (@manzoorwanijk)7655822 #9597 arborist: don't flag inert optional deps in strict-allow-scripts (#9597) (@JamieMagee)00b9f9f #9591 arborist: symlink workspace file: deps on non-workspace local packages (#9591) (@manzoorwanijk)`fc3ef5a` #9559 adapt to @npmcli/run-script@11 breaking changes (@owlstronaut)
npm now supports node ^22.22.2 || ^24.15.0 || >=26.0.0ce7681f #9496 packageExtensions for root-owned dependency manifest repairs (#9496) (@manzoorwanijk)1db885c #9439 native dependency patching (npm patch add/commit/update/ls/rm) (#9439) (@manzoorwanijk)be8053c #9544 warn when min-release-age blocks an audit fix (#9544) (@JamieMagee)18eb967 #9559 bump to new node engine range (@owlstronaut)c3e1a71 #9532 add min-release-age-exclude config (@JamieMagee, @caseyjhol)5cd5150 #9424 default-deny install scripts (allowScripts opt-in) [v12] (@JamieMagee)64e3f79 #9480 allowScripts tooling and inBundle hardening (#9480) (@JamieMagee)7068d42 #9360 Phase 1 of allowScripts opt-in install-script policy (#9360) (@JamieMagee)e96a7de #8703 Preserve https protocol when working with git (#8703) (@oldium)afce424 #9551 arborist: expose store node_modules via NODE_PATH for linked-strategy install scripts (#9551) (@manzoorwanijk)8bbd70d #9550 arborist: allow-remote exemption for proxy/mirror-fronted registry tarballs (#9550) (@manzoorwanijk)315e3bd #9574 arborist: drop orphaned patch entry on uninstall instead of EPATCHUNUSED (#9574) (@manzoorwanijk)62b0694 #9576 patch: explain out-of-sync lockfile after --ignore-patch-failures (#9576) (@manzoorwanijk)cfda867 #9570 arborist: warn once for workspace packageExtensions selector match (#9570) (@manzoorwanijk)f9c977c #9569 arborist: re-apply packageExtensions to the linked actual tree (#9569) (@manzoorwanijk)fc3ef5a #9559 adapt to @npmcli/run-script@11 breaking changes (@owlstronaut)fc6268a #9523 keep nested file: deps and re-resolve changed git refs (#9523) (@owlstronaut)34dbdf5 #9525 arborist: enforce allowScripts for file:/link: dep scripts (@JamieMagee)d70e116 #9510 arborist: honor allow-remote=root for root-direct remote tarballs (#9510) (@manzoorwanijk)4bcba54 #9495 arborist: apply registry-tarball allow-remote exemption in linked strategy (#9495) (@manzoorwanijk)2cbb13b #9490 recognize allowScripts for local link targets (#9490) (@cyphercodes, @cyphercodes)bf623e0 #9473 validate registry path for allow-remote tarballs (@Abhinav-143x)a105799 #9461 arborist: link meta-only optional peers in linked strategy (@manzoorwanijk)275bc69 #9441 arborist: clean up orphaned scoped store entries in linked strategy (@manzoorwanijk)9f3c97f #9452 sanitize package name in linked-strategy path construction (@owlstronaut)a81f2f8 #9428 arborist: read install scripts from disk on lockfile installs instead of a sentinel (@JamieMagee)c5292fa #9422 use prerelease strategy without a bug (@owlstronaut)dac7ff6 #9399 arborist: drop self-link materialization for undeclared workspaces (#9399) (@manzoorwanijk)b77850e #9395 skip hidden lockfile save on dry run (#9395) (@puneetdixit200, @puneetdixit200)cc45055 #9559 @npmcli/node-gyp@6.0.0a12e2c8 #9559 @npmcli/name-from-folder@5.0.0cc96d57 #9559 @npmcli/installed-package-contents@5.0.0b62db95 #9559 bin-links@7.0.02f5da83 #9559 @npmcli/fs@6.0.01502286 #9559 ssri@14.0.021df0ab #9559 proc-log@7.0.08f85646 #9559 parse-conflict-json@6.0.0a44c1cf #9559 pacote@22.0.01f9c567 #9559 npm-registry-fetch@20.0.1998ff1d #9559 npm-pick-manifest@12.0.0d80859a #9559 npm-package-arg@14.0.05e1d513 #9559 npm-install-checks@9.0.0471309f #9559 nopt@10.0.1d867351 #9559 hosted-git-info@10.1.166d46bc #9559 cacache@21.0.19d13ebf #9559 @npmcli/run-script@11.0.027c4dcc #9559 @npmcli/redact@5.0.00be6ae2 #9559 @npmcli/package-json@8.0.0f86a019 #9559 @npmcli/metavuln-calculator@10.0.04d234b2 #9559 @npmcli/map-workspaces@6.0.0npm shrinkwrap is removed, the shrinkwrap config alias is removed, and npm-shrinkwrap.json is no longer loaded or honored at the project root or from
npm shrinkwrap is removed, the shrinkwrap config alias is removed, and npm-shrinkwrap.json is no longer loaded or honored at the project root or from inside dependency tarballs. Rename project-root npm-shrinkwrap.json to package-lock.json; use bundleDependencies if you need to ship a locked dependency tree.e0f12f7 #9348 add allow-git/allow-file/allow-directory/allow-remote configs (@owlstronaut)b8655c7 #9282 arborist: add lockfileString() for in-memory lockfile generation (@ljharb)2e5dcad #9262 drop npm-shrinkwrap.json support (@owlstronaut)822ce86 #9343 arborist: skip lockfile entries for optional deps with incomplete manifests (#9343) (@ecanturk, @owlstronaut)2c9587e #9359 arborist: only forward Link overrides when a rule names a target dep (@manzoorwanijk)f550eb4 #9348 refactor #failureNode, adjust tests and safety (@owlstronaut)1f17566 #9348 allow-remote=none does not block registry tarballs (@owlstronaut)81793ae #9332 arborist: skip extraneous fsChildren in linked-strategy reify (@manzoorwanijk)4c7f6ba #9330 arborist: prune removed-workspace entries from package-lock.json (@manzoorwanijk)076551b #9309 arborist: clean up orphan top-level symlinks in linked strategy (#9309) (@manzoorwanijk)32940e2 #9299 arborist: ignore hidden entries in global update (#9299) (@Grynn)0629fbf #9283 prefer existing tree nodes for peerOptional deps (#9249) (#9283) (@everett1992)bc32d94 #9198 arborist: propagate overrides through Link nodes to targets (#9198) (@manzoorwanijk)1ab20c8 #9235 arborist: fix infinite loop with bundledDependencies and overrides (#9235) (@everett1992)0dc5585 #9167 arborist: handle npm link with install-strategy=linked (@manzoorwanijk)1d058b0 #9221 arborist: do not install inert optional extraneous shared dependencies (#9221) (@lovell)dcad8ec #9206 pass _isRoot context where missing (#9206) (@wraithgar)Compare
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
`21ea382` #9110 arborist: resolve sibling override sets via common ancestor (#9110) (@manzoorwanijk)
21ea382 #9110 arborist: resolve sibling override sets via common ancestor (#9110) (@manzoorwanijk)51365b1 #9107 arborist: update store symlinks when hash changes in linked strategy (#9107) (@manzoorwanijk)8e0a731 #9108 arborist: skip linked actual tree diff in package-lock-only mode (#9108) (@manzoorwanijk)`94bfef5` #9044 audit: exclude locally linked packages from vulnerability audit (#9044) (@lucas-gomes-santana)
5b7c0cc #9096 arborist: exclude store nodes from :root > * in linked strategy (#9096) (@manzoorwanijk)3b70a9d #9097 arborist: simplify rootDeclaredDeps initialization (#9097) (@manzoorwanijk)c7702d0 #9094 arborist: fix non-idempotent linked install with workspace projects (#9094) (@manzoorwanijk)1a744b5 #9081 arborist: omit root dev deps in linked strategy when shared with workspaces (#9081) (@manzoorwanijk)ff51827 #9076 arborist: do not hoist undeclared workspaces in linked strategy (#9076) (@manzoorwanijk)1206f8b #9069 consolidate isolated node/link attributes (#9069) (@wraithgar)a774fb7 #9066 arborist: respect --omit flag in linked install strategy (#9066) (@manzoorwanijk)8614b2a #9031 arborist: avoid full reinstall on subsequent linked strategy runs (#9031) (@manzoorwanijk)16fbe13 #9030 resolve relative file: dependencies correctly with install-strategy=linked (#9030) (@manzoorwanijk)983742b #9055 isolated mode code cleanup (#9055) (@wraithgar)a29aeee #9028 arborist: retry bin-links on Windows EPERM (#9028) (@manzoorwanijk)10d5302 #9051 arborist: unwrap Link nodes in legacyPeerDeps for linked strategy (#9051) (@manzoorwanijk)94bfef5 #9044 audit: exclude locally linked packages from vulnerability audit (#9044) (@lucas-gomes-santana)26fa40e #9041 fix workspace-filtered install with linked strategy (@owlstronaut)`4fcd352` #9017 add :type(registry) to query selector syntax (#9017) (@wraithgar)
`bb135cc` #8981 arborist: fix peerOptional dependency resolution in buildIdealTree (#8981) (@Saibamen, @cursoragent)
`7c038b7` #8968 add support for git-256 sha lengths (#8968) (@wraithgar)
`f5f6cf7` #8943 config: add --allow-git (@wraithgar)
`f951820` #8919 common-ancestor-path@2.0.0
`0765289` #8721 handle ENOTEMPTY errors in moveFile (@keegancsmith)
`b118364` #8760 undefined override set conflicts shouldn't error (@owlstronaut)
`3225fa3` #8737 fix usage of path of custom registry (#8737) (@flj2mu2)
3225fa3 #8737 fix usage of path of custom registry (#8737) (@flj2mu2)e9f0418 #8689 arborist: improve override conflict detection with semantic comparison (#8689) (@Artur-)05319f0 #8677 code cleanup (#8677) (@wraithgar)49a4eef #8676 use look behind regex for trailing slash stripping (#8676) (@wraithgar)b1aee62 #8645 dep flag calculation (#8645) (@liamcmitchell)8cc9f70 #8723 ssri@13.0.059b3c6a #8723 @npmcli/redact@4.0.06cb77df #8723 @npmcli/installed-package-contents@4.0.005ac7a7 #8723 proc-log@6.0.00a74f6d #8723 bin-links@6.0.0041b9b2 #8723 parse-conflict-json@5.0.1a1b0fea #8723 @npmcli/name-from-folder@4.0.03404dca #8723 npm-install-checks@8.0.0542fcf3 #8723 @npmcli/node-gyp@5.0.0`0a8b8c2` #8621 typo bugs and other spelling fixes (#8621) (@jsoref)
`60aa94b` #8576 attach path to json parse error (@wraithgar)
60aa94b #8576 attach path to json parse error (@wraithgar)1eedf82 #8576 use @npmcli/package-json to parse package.json (@wraithgar)f6c868d #8566 calculate omit in diff (#8566) (@liamcmitchell, Liam Mitchell)d389614 #8579 corrects peer dependency flag propagation (@owlstronaut)566f1b7 #8576 minimatch@10.0.3ea7ca5f #8576 lru-cache@11.2.1bf6b686 #8576 npm-package-arg@13.0.09392488 #8576 npm-package-manifest@11.0.1633c4ed #8576 hosted-git-info@9.0.01149971 #8576 npm-registry-fetch@19.0.06221e27 #8576 @npmcli/metavuln-calculator@9.0.2da81a37 #8576 cacache@20.0.16b4c5f9 #8576 @npmcli/run-script@10.0.0b6bb9ae #8576 pacote@21.0.31b4433f #8576 @npmcli/map-workspaces@5.0.0ceae674 #8576 @npmcli/package-json@7.0.14f37534 #8576 remove read-package-json-fast`208c06e` #8448 peer edge crash due to no parent or detached node (#8448) (@milaninfy)
208c06e #8448 peer edge crash due to no parent or detached node (#8448) (@milaninfy)3b54e9c #8534 installLinks works with transitive external file dependencies (#8534) (@owlstronaut)ed71acb #8473 arborist: #8472 Keeps the registry protocol when modifying resolve URL (#8473) (@Jeepsboucher, Jean-Philippe Boucher)`6dbe21a` #8436 local transitive dependencies with --install-links=true (@owlstronaut)
6dbe21a #8436 local transitive dependencies with --install-links=true (@owlstronaut)8042af3 #8431 prune optional peer dependencies that are no longer explicitly depended on (#8431) (@G-Rath)c457c75 #8430 remove duplicate loop (#8430) (@G-Rath)f7b056f #8400 clean up audit-report code (#8400) (@wraithgar)f163d01 #8372 use omit when checking ideal tree engine (#8372) (@owlstronaut)`887385d` #8356 arborist: use hosted-git-info to correctly parse resolved git urls (#8356) (@milaninfy)
`8f6eb6b` #8312 arborist: fix file dep making wrong link (#8312) (@alexsch01)
`57aa89f` #8265 use run by default and run-script as the alias (#8265) (@owlstronaut)
d5bcf38 #8268 arborist: Add better error message when lockfile is malformed (#8268) (@owlstronaut)5e1fed9 #8290 arborist: improve README markdown (#8290) (@mbtools)0886e7a #8222 preserve registry path when replacing a host (@owlstronaut)815311b #8206 arborist: workspaces correctly path to file: packages from overrides (@owlstronaut)`a96d8f6` #8184 arborist: omit failed optional dependencies from installed deps (#8184) (@owlstronaut, @zkat)
a96d8f6 #8184 arborist: omit failed optional dependencies from installed deps (#8184) (@owlstronaut, @zkat)04f53ce #8180 arborist: safely fallback on unresolved $ dependency references (#8180) (@owlstronaut)885accd #8185 arborist: only replace hostname for resolved URL (#8185) (@billy-briggs-dev)8b7bb12 #8168 arborist: Allow downgrades to hoisted version dedupe workspace i… (#8168) (@owlstronaut)1642556 #8160 arborist: workspaces respect overrides on subsequent installs (#8160) (@owlstronaut)`b9225e5` #8089 resolve override conflicts and apply correct versions (#8089) (@owlstronaut)
`a7bfc6d` #7972 trigger release process (#7972) (@wraithgar)
Upon publishing, in order to apply a default "latest" dist tag, the command now retrieves all prior versions of the package. It will require that the
bun.lockb files are now included in the strict ignore list during packing--ignore-scripts now applies to all lifecycle scripts, include prepare
--ignore-scripts now applies to all lifecycle scripts, include prepare^20.17.0 || >=22.9.0080a0f2 #7911 remove old audit fallback request (@wraithgar)3ffc08b #7831 for @npmcli/arborist sets node engine range to ^20.17.0 || >=22.9.0 (@reggi)Nothing published for this version
Nothing published for this version
workspace : @npmcli/arborist@10.0.3
@npmcli/arborist@10.0.3Nothing published for this version
Nothing published for this version
@npmcli/arborist now supports node ^18.17.0 || >=20.5.0
@npmcli/arborist now supports node ^18.17.0 || >=20.5.05795987 #7803 update proggy@3.0.099ccae3 #7803 update bin-links@5.0.075786ad #7803 update @npmcli/query@4.0.01c25a1d #7803 update @npmcli/node-gyp@4.0.02d7fc3d #7803 update @npmcli/name-from-folder@3.0.01e09334 #7803 update @npmcli/metavuln-calculator@8.0.0820e983 #7803 update @npmcli/installed-package-contents@3.0.09cd6603 #7803 update read-package-json-fast@4.0.08206c4f #7803 update ssri@12.0.0f6909a0 #7803 update proc-log@5.0.0f9b2e18 #7803 update parse-conflict-json@4.0.0e7ab206 #7803 update pacote@19.0.0d13a20b #7803 update npm-registry-fetch@18.0.1092f41f #7803 update npm-pick-manifest@10.0.050a7bc8 #7803 update npm-package-arg@12.0.0591130d #7803 update npm-install-checks@7.1.0105fa2b #7803 update nopt@8.0.07214149 #7803 update json-parse-even-better-errors@4.0.06deae9e #7803 update hosted-git-info@8.0.0034c729 #7803 update cacache@19.0.1538a4cc #7803 update @npmcli/run-script@9.0.1b80d048 #7803 update @npmcli/redact@3.0.02076368 #7803 update @npmcli/package-json@6.0.1feac87c #7803 update @npmcli/map-workspaces@4.0.1dd90f9e #7803 update @npmcli/fs@4.0.0`6f33d74` #7579 arborist: safeguard against null node.target in flag calculation (#7579) (@AmirSa12)
`2d1d8d0` #7559 adds node: specifier to all native node modules (#7559) (@reggi)
`12f103c` #7533 add first param titles to logs where missing (#7533) (@lukekarrys)
12f103c #7533 add first param titles to logs where missing (#7533) (@lukekarrys)e290352 #7499 revert DepsQueue to re-sort on pop() (#7499) (@lukekarrys)56a27fa #7494 avoid caching manifests as promises (@wraithgar)722c0fa #7463 limit packument cache size based on heap size (@wraithgar)effe910 #7475 don't omit license from stored manifests (#7475) (@lukekarrys)fd42986 #7498 @npmcli/fs@3.1.1ea0b07d #7482 pacote@18.0.65b2317b #7463 add lru-cache7e15b6d #7480 @npmcli/metavuln-calculator@7.1.18b20f8c #7480 ssri@10.0.6a9a6dcd #7480 pacote@18.0.5e2fdb65 #7480 npm-pick-manifest@9.0.1e71f541 #7480 nopt@7.2.118c3b40 #7480 json-parse-even-better-errors@3.0.2714e3e1 #7480 hosted-git-info@7.0.2f94d672 #7480 cacache@18.0.343331e4 #7480 bin-links@4.0.463ef498 #7457 npm-registry-fetch@17.0.1`9123de4` #7373 do all output over proc-log events (@lukekarrys)
9123de4 #7373 do all output over proc-log events (@lukekarrys)9622597 #7339 refactor terminal display (#7339) (@lukekarrys)78447d7 #7399 prefer fs/promises over promisify (#7399) (@lukekarrys)6512112 #7378 use proc-log for all timers (@lukekarrys)36adff3 #7408 pacote@18.0.2486d46c #7408 @npmcli/installed-package-contents@2.1.0157d0ae #7408 @npmcli/package-json@5.1.0fc6e291 #7392 proc-log@4.2.0 (#7392)38ed048 #7378 @npmcli/metavuln-calculator@7.1.07678a3d #7378 proc-log@4.1.087f6c09 #7373 @npmcli/metavuln-calculator@7.0.1b8f8b41 #7373 @npmcli/run-script@8.0.079f79c7 #7373 proc-log@4.0.09027266 #7373 pacote@18.0.0ee4b3e0 #7373 npm-registry-fetch@16.2.1ac98fd3 #7373 npm-package-arg@11.0.29351570 #7373 @npmcli/package-json@5.0.3`ef381b1` #7363 use @npmcli/redact for url cleaning (#7363) (@lukekarrys)
`8cab136` #7324 ensure maxSockets is respected (#7324) (@lukekarrys)
`2366edc` #7218 query: add :vuln pseudo selector (@wraithgar)
`6673c77` #6914 add --libc option to override platform specific install (#6914) (@wraithgar, @Brooooooklyn)
`ae2d982` #7027 arborist: node.target can be null when it is a file dep or symlink (#7027) (@ljharb, @lukekarrys)
`dfb6298` #6937 node-gyp@10.0.0
`81a460f` #6732 add package-lock-only mode to npm query (@wraithgar)
81a460f #6732 add package-lock-only mode to npm query (@wraithgar)0d29855 #6732 add no-package-lock mode to npm audit (@wraithgar)0860159 #6829 ensure workspace links query parents correctly (#6829) (@Carl-Foster)bef7481 #6782 query with workspace descendents (#6782) (@bdehamer)`1c93c44` #6755 Add --cpu and --os option to override platform specific install (#6755) (@yukukotani)
`fb31c7e` trigger release process (@lukekarrys)
fb31c7e trigger release process (@lukekarrys)support for node <=16.13 has been removed
6b251b1 #6706 drop node 16.13.x support (@lukekarrys)e3a377d #6706 drop node14 support (@lukekarrys)eb41977 #6706 @npmcli/run-script@7.0.1f334466 #6706 pacote@17.0.4bb63bf9 #6706 @npmcli/run-script@7.0.043831d0 #6706 pacote@17.0.344e8fec #6706 pacote@17.0.22ee0fb3 #6706 npm-registry-fetch@16.0.081ff4df #6706 pacote@17.0.1c3a1a02 #6706 @npmcli/metavuln-calculator@7.0.0cac0725 #6706 pacote@17.0.0fd8beaf #6706 npm-pick-manifest@9.0.0c784b57 #6706 npm-package-arg@11.0.0729e893 #6706 hosted-git-info@7.0.07af81c7 #6706 cacache@18.0.0b0849ab #6706 @npmcli/package-json@5.0.061e9b00 #6706 @npmcli/metavuln-calculator@6.0.14c9eb17 #6706 npm-install-checks@6.2.088ece81 #6706 npm-pick-manifest@8.0.29117a4f #6706 ssri@10.0.55eea975 #6706 cacache@17.1.4ca33c98 #6706 @npmcli/metavuln-calculator@6.0.0edbc25a #6706 pacote@16.0.05d0d859 #6706 npm-registry-fetch@15.0.0Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →