NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2872 most downloaded on npm
Programmatic API to update package.json
Last release 4 months ago
22 May 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 26 of 28 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
28 releases · first in 2021
One column per quarter.
@npmcli/package-json now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
@npmcli/package-json now supports node ^22.22.2 || ^24.15.0 || >=26.0.0b0ebae1 #185 bump to new node engine range (@owlstronaut)5898ac5 #185 template-oss-apply (@owlstronaut)2ac3b34 #177 normalize the top-level overrides field (@owlstronaut)057fd25 #174 remove magic "server.js" handling (@owlstronaut)126f578 #185 proc-log@7.0.0fe58bf6 #185 json-parse-even-better-errors@6.0.059d01ac #185 hosted-git-info@10.1.11f2ff5f #185 @npmcli/git@8.0.03188f3d #185 snapshot update for hosted-git-info change (@owlstronaut)c433eb8 #185 @npmcli/eslint-config@7.0.0 (@owlstronaut)6212bdf #185 template-oss-apply (@owlstronaut)c23823f #185 bumping @npmcli/template-oss from 4.29.0 to 5.1.0 (@owlstronaut)1affdf1 #174 template-oss-apply (@owlstronaut)ece3cb6 #170 bump @npmcli/template-oss from 4.28.1 to 4.29.0 (#170) (@dependabot[bot], @npm-cli-bot)09b981d #172 inline license validation code ( @wraithgar )
09b981d #172 inline license validation code (@wraithgar)bd3b7ea #169 bump @npmcli/template-oss from 4.28.0 to 4.28.1 (#169) (@dependabot[bot], @npm-cli-bot)e33b13e #167 bump glob from 12.0.0 to 13.0.0 ( #167 ) ( @dependabot [bot])
e33b13e #167 bump glob from 12.0.0 to 13.0.0 (#167) (@dependabot[bot])57952b8 #164 prevent crash when expanding directories.bin without filesystem path ( #164 ) ( @MaxBlack-dev , Max Black)
57952b8 #164 prevent crash when expanding directories.bin without filesystem path (#164) (@MaxBlack-dev, Max Black)ba5c736 #165 bump glob from 11.1.0 to 12.0.0 (#165) (@dependabot[bot])7f3afb6 #156 comment typo ( #156 ) ( @Clozent )
0393243 #160 bump proc-log from 5.0.0 to 6.0.0 (#160) (@dependabot[bot])f3c7926 #161 bump json-parse-even-better-errors from 4.0.0 to 5.0.0 (#161) (@dependabot[bot])4a80b15 #162 bump @npmcli/eslint-config from 5.1.0 to 6.0.0 (#162) (@dependabot[bot])e093242 #163 bump @npmcli/template-oss from 4.27.1 to 4.28.0 (#163) (@dependabot[bot], @npm-cli-bot)7.0.1 (2025-09-17) Dependencies 1364087 #153 @npmcli/git@7.0.0
4695e87 #150 use URL.canParse instead of runtime deprecated url.parse api ( #150 ) ( @SuperchupuDev )
package-json now supports node ^20.17.0 || >=22.9.09dd0eb5 #144 add syncNormalize (@wraithgar)08eae47 #144 add binDir step to normalize function (@wraithgar)a5e4ac3 #152 align to npm 11 node engine range (@owlstronaut)4695e87 #150 use URL.canParse instead of runtime deprecated url.parse api (#150) (@SuperchupuDev)dbc9ef1 #144 require an object in fromContent() (@wraithgar)f06eb18 #144 remove unused bundleDependenciesFalse (@wraithgar)a8b1cc9 #144 secure and unixify paths discovered via directories.bin (@wraithgar)23c29a9 #144 remove erroneous bundledDependencies log (@wraithgar)a179a87 #144 fix tests to await async normalize (@wraithgar)203fec8 #144 remove read-package-json (@wraithgar)7bde184 #144 remove read-package-json-fast (@wraithgar)394192d #144 remove backward compatiblity tests (@wraithgar)6e89e39 #148 bump @npmcli/template-oss from 4.23.6 to 4.25.0 (#148) (@dependabot[bot], @owlstronaut)228539f #145 adds fixName step for publishing ( #145 ) ( @owlstronaut )
526473b #139 remove max-len linting bypasses ( @wraithgar )
526473b #139 remove max-len linting bypasses (@wraithgar)2a7bbe5 #139 inline normalize-package-data logic (@wraithgar)2d320bc #140 save when reverting content (@wraithgar)0930f4e #139 @npmcli/eslint-config@5.1.0 (@wraithgar)1464adc #140 scope test fixture package names (@wraithgar)d722a1f #137 bump @npmcli/template-oss from 4.23.5 to 4.23.6 (#137) (@dependabot[bot], @npm-cli-bot)4c22738 #133 adds ability to sort package.json on save ( #133 ) ( @reggi , @wraithgar )
4c22738 #133 adds ability to sort package.json on save (#133) (@reggi, @wraithgar)6fef3a2 #135 bump @npmcli/template-oss from 4.23.3 to 4.23.5 (#135) (@dependabot[bot], @npm-cli-bot)`25e2a76` #129 bump @npmcli/git@6.0.0
@npmcli/package-json now supports node ^18.17.0 || >=20.5.0
`962b9e1` #119 hidden dir path clean up corrected (#119) (@milaninfy)
`62e585a` #106 add readPackage helper (#106) (@wraithgar)
`54756d2` #105 apply securePath to package bin (#105) (@antongolub)
54756d2 #105 apply securePath to package bin (#105) (@antongolub)46c563b add normalizePackageMan helper (#100) (@antongolub)a974274 prevent directory.man referencing outside the package root (#104) (@antongolub)191b521 #102 invalid scripts warning fixed for undefined scripts (#102) (@milaninfy)`17788d0` #96 add fromContent method to set contents directly (#96) (@lukekarrys)
## 5.0.3 (2024-04-12) ### Dependencies * `28f09ed` #92 proc-log@4.0.0
`fda5722` #87 perf: lazy load un-common dependencies for npm run (#87) (@H4ad)
fda5722 #87 perf: lazy load un-common dependencies for npm run (#87) (@H4ad)71f09d6 #88 perf: only import necessary functions from semver (#88) (@H4ad)66e0c23 #80 postinstall for dependabot template-oss PR (@lukekarrys)00e4bbb #80 bump @npmcli/template-oss from 4.21.1 to 4.21.3 (@dependabot[bot])d784aa8 #77 postinstall for dependabot template-oss PR (@lukekarrys)efeee22 #77 bump @npmcli/template-oss from 4.19.0 to 4.21.1 (@dependabot[bot])a4df4cf #56 bump read-package-json from 6.0.4 to 7.0.0 (@dependabot[bot])f7c048a #58 postinstall for dependabot template-oss PR (@lukekarrys)6240313 #58 bump @npmcli/template-oss from 4.18.1 to 4.19.0 (@dependabot[bot])5ab117c #57 postinstall for dependabot template-oss PR (@lukekarrys)f56390e #57 bump @npmcli/template-oss from 4.18.0 to 4.18.1 (@dependabot[bot])support for node 14 has been removed
`04bc9cf` #49 don't report node_modules/.bin fix unless it happened (@wraithgar)
04bc9cf #49 don't report node_modules/.bin fix unless it happened (@wraithgar)3c1cb66 #49 inline bin normalization code (@wraithgar)e97e423 #48 properly parse strict flag on version check (#48) (@wraithgar)3bcf2fd #47 only report bundleDependencies change if it was changed (@wraithgar)09d8573 #47 pull in fix logic from normalize-package-data (@wraithgar)60a09da #44 check for changes array during author step (#44) (@wraithgar)the path parameter is now tied to load and not the class constructor.
`9e0859b` #36 make prepare and normalize have feature parity with legacy packages (@lukekarrys)
`f32c0d9` #32 add prepare function (@wraithgar)
@npmcli/package-json is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0
@npmcli/package-json is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0this drops support for node10 and non-LTS versions of node 12 and node 14
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →