NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2301 most downloaded on npm
Get a list of the files to add from a folder into an npm package
Last release 3 months ago
22 Jun 2026
Release timing varies
gaps range from 2 weeks to 9 months
Some releases are documented
notes for 29 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
9 years old
72 releases · first in 2017
ec0f6c4 #294 exclude root .npm-extension.mjs / .cjs from package tarballs ( #294 ) ( @manzoorwanijk )
ec0f6c4 #294 exclude root .npm-extension.mjs/.cjs from package tarballs (#294) (@manzoorwanijk)d5ab08c #293 bump @npmcli/template-oss from 5.1.0 to 5.1.1 (#293) (@dependabot[bot], @npm-cli-bot)One column per quarter.
7e2513d #291 exclude patchedDependencies patch files from the package tarball ( #291 ) ( @manzoorwanijk )
7e2513d #291 exclude patchedDependencies patch files from the package tarball (#291) (@manzoorwanijk)1369ec3 #287 support a user level ignore file via globalIgnoreFile ( #287 ) ( @ljharb )
npm-packlist now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
npm-packlist now supports node ^22.22.2 || ^24.15.0 || >=26.0.0files[] are now interpreted as glob patterns anchored to the package root, with no special-case overrides. Slashless negations like !readme.md only match at the root — use !**/readme.md to remove at every depth. An exact file path in files[] no longer overrides a nested .npmignore rule that excludes it; remove the rule from .npmignore if you need such a file to ship. Listing a default-ignored file (e.g. .npmignore, .npmrc) in files[] no longer forces it to be packed.npm-shrinkwrap.json is no longer included in published tarballs by default. Publishers who need to ship a locked dependency tree should use bundleDependencies; publishers with a legitimate reason to include a file literally named npm-shrinkwrap.json can still opt back in with a negated files entry.da9502e #286 bump to new node engine range (@owlstronaut)943b8ec #286 template-oss-apply (@owlstronaut)2ec1c00 #281 exclude npm-shrinkwrap.json from package contents (@owlstronaut)59a8d0f #279 exclude bun.lock from package contents (@owlstronaut)8e8d6ee #282 use real glob semantics for package.json files array (@owlstronaut)e768b3a #286 template-oss-apply (@owlstronaut)b1c2c16 #286 bumping @npmcli/template-oss from 4.30.0 to 5.1.0 (@owlstronaut)13f4e2b #279 template-oss-apply (@owlstronaut)261224f #278 bump @npmcli/template-oss from 4.29.0 to 4.30.0 (#278) (@dependabot[bot], @npm-cli-bot)ae8cbee #276 only warn about gitignore fallback at package root, not subdirectories ( #276 ) ( @umeshmore45 )
ae8cbee #276 only warn about gitignore fallback at package root, not subdirectories (#276) (@umeshmore45)de1e875 #272 bump @npmcli/eslint-config from 5.1.0 to 6.0.0 (#272) (@dependabot[bot])04102d9 #275 bump @npmcli/template-oss from 4.28.1 to 4.29.0 (#275) (@dependabot[bot], @npm-cli-bot, @owlstronaut)7b4c677 #270 bump proc-log from 5.0.0 to 6.0.0 ( #270 ) ( @dependabot [bot])
7b4c677 #270 bump proc-log from 5.0.0 to 6.0.0 (#270) (@dependabot[bot])c23dea8 #269 bump @npmcli/template-oss from 4.26.0 to 4.27.1 (#269) (@dependabot[bot], @npm-cli-bot)566ffc2 #265 log warning for .gitignore versus .npmignore logic ( #265 ) ( @simwai )
5d905ef #266 bump @npmcli/template-oss from 4.25.0 to 4.25.1 (#266) (@dependabot[bot], @npm-cli-bot)7e5f43b #256 bump @npmcli/arborist from 8.0.0 to 9.0.0 ( #256 ) ( @dependabot [bot])
7e5f43b #256 bump @npmcli/arborist from 8.0.0 to 9.0.0 (#256) (@dependabot[bot])7e3cd57 #261 bump @npmcli/template-oss from 4.24.4 to 4.25.0 (#261) (@dependabot[bot], @owlstronaut)this module is now compatible with the following node versions: ^20.17.0 || >=22.9.0
bun.lockb is now included in the strict ignorelist9f74fd3 #168 add bun.lockb to ignorelist (#168) (@antongolub)67fef03 update engines to ^20.17.0 || >=22.9.0 (#254) (@wraithgar)fd425fa bump @npmcli/eslint-config from 4.0.5 to 5.0.1 (#250) (@dependabot[bot])3b66b5a #252 bump @npmcli/arborist from 7.5.4 to 8.0.0 (#252) (@dependabot[bot])e688d26 bump @npmcli/template-oss from 4.23.3 to 4.23.4 (#251) (@dependabot[bot], @npm-cli-bot)npm-packlist now supports node ^18.17.0 || >=20.5.0
npm-packlist now supports node ^18.17.0 || >=20.5.04679b12 #247 align to npm 10 node engine range (@hashtagchris)46ed801 #245 bump @npmcli/eslint-config from 4.0.5 to 5.0.0 (#245) (@dependabot[bot])625ddca #240 bump @npmcli/arborist from 6.5.1 to 7.5.4 (#240) (@dependabot[bot])e2eb28d #247 run template-oss-apply (@hashtagchris)3c27bb3 #230 bump @npmcli/template-oss to 4.22.0 (@lukekarrys)fa9e80d #242 bump @npmcli/template-oss from 4.22.0 to 4.23.3 (#242) (@dependabot[bot])cb4a823 #230 postinstall for dependabot template-oss PR (@lukekarrys)`8fc4df1` #204 always ignore .npmrc files at every level (@wraithgar)
8fc4df1 #204 always ignore .npmrc files at every level (@wraithgar)cd5ddbd #205 preserve slashes in specified files (#205) (@mohd-akram)20fe0cd #207 bump @npmcli/template-oss from 4.21.1 to 4.21.2 (#207) (@dependabot[bot], @lukekarrys)f8be7bd #202 bump @npmcli/template-oss from 4.19.0 to 4.21.1 (#202) (@dependabot[bot], @lukekarrys)8e1d900 #204 tests reflect fixed ignore-walk rules (@wraithgar)6d7cbe9 #181 postinstall for dependabot template-oss PR (@lukekarrys)80ec501 #181 bump @npmcli/template-oss from 4.18.1 to 4.19.0 (@dependabot[bot])f327738 #179 postinstall for dependabot template-oss PR (@lukekarrys)a770a96 #179 bump @npmcli/template-oss from 4.18.0 to 4.18.1 (@dependabot[bot])The files array can now be used to exclude non-root readme, license, licence, and copying files.
`e5256de` #149 skip missing optional deps when bundling, closes npm/cli#5924 (#149) (@nlf)
`c6f2b69` #147 treat glob the same as globstar (#147) (@lukekarrys)
`d5b653c` #140 account for directories and files prefixed with ./ (#140) (@wraithgar)
`250d589` #136 bump ignore-walk from 5.0.1 to 6.0.0
`b83e0aa` #133 set as release (@fritzy)
if npm-shrinkwrap.json is included in your .npmignore, the shrinkwrap will now be excluded from your packlist.
tree is now the first parameter
tree is now the first parameter`f823be6` #125 arborist@5||6||6.pre
this module now follows a strict order of operations when applying ignore rules. if a files array is present in the package.json, then rules in .gitig
files array is present in the package.json, then rules in .gitignore and .npmignore files from the root will be ignored.npm-packlist is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0bump npm-bundled from 1.1.2 to 2.0.0
bump npm-normalize-package-bin from 1.0.1 to 2.0.0
correctly ignore .gitignore when a .npmignore is present
correctly handle workspace roots
do not pack workspaces by default
strip leading ./ from files array entries
normalize win32 paths before globbing
### 5.0.1 (2022-04-20) ### Dependencies * bump glob from 7.2.0 to 8.0.1
replace deprecated String.prototype.substr()
This drops support for node10 and non-LTS versions of node12 and node14
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →