NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #989 most downloaded on npm
Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.
Last release 3 months ago
09 Jun 2026
Release timing varies
gaps range from 3 weeks to 10 months
Most releases are documented
notes for 48 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
110 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
verify: size param no longer lost in a verify (#131) (c614a19), closes #130
opts: use figgy-pudding for opts
Nothing published for this version
<a name="10.0.3"></a>
content: rethrow aggregate errors as ENOENT
ls: deleted entries could cause a premature stream EOF
move-file: actually use the fallback to move-concurrently
move-concurrently (#110) (073fbe1)<a name="10.0.0"></a>
<a name="9.3.0"></a>
<a name="9.2.9"></a>
Nothing published for this version
Nothing published for this version
<a name="9.2.8"></a>
### Bug Fixes * ssri: bump ssri for bugfix
content: make verified content completely read-only
node: update ssri to prevent old node 4 crash
deps: fix lockfile issues and bump ssri
### Bug Fixes * deps: bumping deps
rm: stop crashing if content is missing on rm
i18n: lets pretend this didn't happen
docs: fixing translation messup
<a name="9.2.0"></a>
<a name="9.1.0"></a>
<a name="9.0.0"></a>
<a name="8.0.0"></a>
{sri, size} instead of sri. Use result.sri anywhere that needed the old return value.<a name="7.1.0"></a>
<a name="7.0.5"></a>
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
integrity: new ssri with fixed integrity stream
fix-owner: throw away ENOENTs on chownr
read: fixing error message for integrity verification failures
<a name="7.0.2"></a>
integrity: use EINTEGRITY error code and update ssri
Content entries will remain intact, and existing caches will automatically reuse any content from before this breaking change.
<a name="7.0.0"></a>
integrity: The entire API has been overhauled to use SRI hashes instead of digest/hashAlgorithm pairs. SRI hashes follow the Subresource Integrity standard and support strings and objects compatible with ssri.
This change bumps the index version, which will invalidate all previous index entries. Content entries will remain intact, and existing caches will automatically reuse any content from before this breaking change.
cacache.get.info(), cacache.ls(), and cacache.ls.stream() will now return objects that looks like this:
{
key: String,
integrity: '<algorithm>-<base64hash>',
path: ContentPath,
time: Date<ms>,
metadata: Any
}
opts.digest and opts.hashAlgorithm are obsolete for any API calls that used them.
Anywhere opts.digest was accepted, opts.integrity is now an option. Any valid SRI hash is accepted here -- multiple hash entries will be resolved according to the standard: first, the "strongest" hash algorithm will be picked, and then each of the entries for that algorithm will be matched against the content. Content will be validated if any of the entries match (so, a single integrity string can be used for multiple "versions" of the same document/data).
put.byDigest(), put.stream.byDigest, get.byDigest() and get.stream.byDigest() now expect an SRI instead of a digest + opts.hashAlgorithm pairing.
get.hasContent() now expects an integrity hash instead of a digest. If content exists, it will return the specific single integrity hash that was found in the cache.
verify() has learned to handle integrity-based caches, and forgotten how to handle old-style cache indices due to the format change.
cacache.rm.content() now expects an integrity hash instead of a hex digest.
<a name="6.3.0"></a>
<a name="6.2.0"></a>
<a name="6.1.2"></a>
Nothing published for this version
Nothing published for this version
Nothing published for this version
index: set default hashAlgorithm
coverage: bumping coverage for verify
<a name="6.1.0"></a>
<a name="6.0.2"></a>
Nothing published for this version
index: segment cache items with another subbucket
api: keep memo cache mostly-internal
<a name="6.0.0"></a>
format-number@2.0.2 (1187791)@npmcorp/move@1.0.0 (bdd00bf)bluebird@3.4.7 (3a17aff)promise-inflight@1.0.1 (a004fe6)opts.hashAlgorithm in explicitly.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →