NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2415 most downloaded on npm
Fetch-based http client for use with npm registry APIs
Last release 4 months ago
02 Jun 2026
Release timing varies
gaps range from 9 days to 9 months
Most releases are documented
notes for 37 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
9 years old
84 releases · first in 2017
8d1432f #301 include body.message and fall back to full body in HttpErrorGeneral message ( #301 ) ( @owlstronaut )
8d1432f #301 include body.message and fall back to full body in HttpErrorGeneral message (#301) (@owlstronaut)npm-registry-fetch now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
npm-registry-fetch now supports node ^22.22.2 || ^24.15.0 || >=26.0.03082ebc #298 bump to new node engine range (@owlstronaut)1ccd309 #298 template-oss-apply (@owlstronaut)726f8c2 #298 proc-log@7.0.04875644 #298 npm-package-arg@14.0.0ddfa5ec #298 minipass-fetch@6.0.03be0797 #298 make-fetch-happen@16.0.0c93b239 #298 @npmcli/redact@5.0.0f4862b2 #298 @npmcli/eslint-config@7.0.0 (@owlstronaut)3c07251 #298 ssri@14.0.0 (@owlstronaut)3331264 #298 cacache@21.0.0 (@owlstronaut)3e2c7f1 #298 template-oss-apply (@owlstronaut)7ceab44 #298 bumping @npmcli/template-oss from 4.28.0 to 5.1.0 (@owlstronaut)One column per quarter.
360ec4e #282 @npmcli/redact@4.0.0
d8074d6 #280 add signal opt ( #280 ) ( @clemgbld )
npm-registry-fetch now supports node ^20.17.0 || >=22.9.0
npm-registry-fetch now supports node ^20.17.0 || >=22.9.0364c6c0 #277 align to npm 11 node engine range (@owlstronaut)563fda6 #277 cacache@20.0.0 (@owlstronaut)d5519d6 #277 template-oss apply fix (@owlstronaut)894f3a7 #277 @npmcli/template-oss@4.25.0 (@owlstronaut)8044781 #273 log cache hits distinct from fetch ( #273 ) ( @mbtools )
99b99d2 #269 bump cacache from 18.0.4 to 19.0.1 (#269) (@dependabot[bot])bd3f7d1 #272 bump @npmcli/template-oss from 4.23.3 to 4.23.4 (#272) (@dependabot[bot], @npm-cli-bot)ad9139a #270 bump make-fetch-happen@14.0.0
npm-registry-fetch now supports node ^18.17.0 || >=20.5.0
npm-registry-fetch now supports node ^18.17.0 || >=20.5.078aa620 #266 bump minizlib from 2.1.2 to 3.0.1 (#266)842f324 #264 proc-log@5.0.0b394f34 #264 npm-package-arg@12.0.0c2b986a #264 minipass-fetch@4.0.0351e1f4 #264 @npmcli/redact@3.0.0bd5f617 #262 bump ssri from 10.0.6 to 12.0.0 (#262) (@dependabot[bot])60a396a #264 run template-oss-apply (@reggi)0a9f05b #256 bump @npmcli/eslint-config from 4.0.5 to 5.0.0 (@dependabot[bot])4317115 #257 postinstall for dependabot template-oss PR (@hashtagchris)81080b9 #257 bump @npmcli/template-oss from 4.23.1 to 4.23.3 (@dependabot[bot])29712af #246 merging functionality from minipass-json-stream ( @wraithgar )
29712af #246 merging functionality from minipass-json-stream (@wraithgar)920a3d8 #241 bump @npmcli/template-oss to 4.22.0 (@lukekarrys)17a1013 #241 postinstall for dependabot template-oss PR (@lukekarrys)45cef0a #239 allow HttpErrorBase to take headers object ( @lukekarrys , @wraithgar )
45cef0a #239 allow HttpErrorBase to take headers object (@lukekarrys, @wraithgar)45cef0a #239 make ErrorBase always capture stack trace (#239) (@lukekarrys, @wraithgar)remove undcoumented cleanUrl export
## 16.2.1 (2024-04-12) ### Dependencies * `7a18f69` #232 proc-log@4.0.0
`76b02e8` #231 use @npmcli/redact for url cleaning (#231) (@lukekarrys)
support for node <=16.13 has been removed
Backwards compatibility should be fully implemented but due to the scope of this change it was made a breaking change out of an abundance of caution.
@npmcli/agent. Backwards compatibility should be fully implemented but due to the scope of this change it was made a breaking change out of an abundance of caution.`a2d5880` #177 bump minipass from 4.2.7 to 5.0.0
`15dd221` #178 clean password by using url object itself (#178) (@DEMON1A)
`c669335` #158 bump minipass from 3.3.6 to 4.0.0
`36b7685` #154 bump npm-package-arg from 9.1.2 to 10.0.0
this module no longer attempts to change file ownership automatically
npm-registry-fetch is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0## 13.3.1 (2022-08-15) ### Bug Fixes * linting
respect registry-scoped certfile and keyfile options
set 'npm-auth-type' header depending on config option
replace deprecated String.prototype.substr()
update make-fetch-happen requirement from ^10.0.3 to ^10.0.4
bump minipass-fetch from 1.4.1 to 2.0.1
this drops support for passing in a log property. All logs are now emitted on the process object via proc-log
log property. All logs are now emitted on the process object via proc-loglog property. All logs are now emitted on the process object via proc-logupdate make-fetch-happen requirement from ^10.0.0 to ^10.0.1
### dependencies * @npmcli/template-oss@2.5.1 (cc4cc11) * make-fetch-happen@10.0.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
update minipass and make-fetch-happen to latest (3b6c5d0), closes #23
Nothing published for this version
Nothing published for this version
Removes the 'opts.refer' option and the HTTP Referer header (unless explicitly added to the 'headers' option, of course).
PR-URL: https://github.com/npm/npm-registry-fetch/pull/25 Credit: @isaacs
Nothing published for this version
figgy pudding is now nowhere to be found.
Defaults and behavior are all the same, and this module is now using the canonical camelCase option names that npm v7 will provide to all its deps.
Related to: https://github.com/npm/rfcs/pull/102
PR-URL: https://github.com/npm/npm-registry-fetch/pull/22 Credit: @isaacs
Remove figgy-pudding, use canonical option names (ede3c08), closes #22
update cacache, ssri, make-fetch-happen (57fcc88)
Nothing published for this version
Nothing published for this version
This drops support for node < 10.
There are some lint failures due to standard pushing for using WhatWG URL objects instead of url.parse/url.resolve. However, the code in this lib does some fancy things with the query/search portions of the parsed url object, so it'll take a bit of care to make it work properly.
detect CI so our tests don't fail in CI (5813da6)
Use WhatWG URLs instead of url.parse (8ccfa8a)
normalize settings, drop old nodes, update deps (510b125)
<a name="5.0.1"></a>
prefer const in getAuth function
<a name="5.0.0"></a>
<a name="4.0.2"></a>
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add null check on body on 401 errors (e3a0186), closes #9
<a name="4.0.0"></a>
<a name="3.9.1"></a>
Your coding agent can read these notes before it upgrades. Set up the MCP server →