NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2984 most downloaded on npm
JavaScript package downloader
Last release 3 months ago
15 Jun 2026
Release timing varies
gaps range from 8 days to 9 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
238 releases · first in 2016
pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.09316f5 #504 bump to new node engine range (@owlstronaut)2ab74b0 #497 strip patchedDependencies from the packed package.json (#497) (@manzoorwanijk)66e7ea7 #487 forward globalIgnoreFile option to npm-packlist (@ljharb)ce804fb #498 avoid ReDoS in addGitSha committish stripping (#498) (@owlstronaut)1f5f131 #494 pass --global=false when preparing git dependencies (@owlstronaut)e0af7f6 #486 respect ignoreScripts option for git dependencies (@owlstronaut)12c8c8f #481 fall back to git clone when tarball response is not a valid archive (@babyhuey)61f065a #481 use statusCode instead of constructor name for tarball fallback in git fetcher (@j1mb0-1)6d160c1 #434 do not switch to git+ssh for https repository links (#434) (@oldium)371e8b0 #504 ssri@14.0.0b68c6c2 #504 sigstore@5.0.057793ab #504 proc-log@7.0.033eacc9 #504 npm-registry-fetch@20.0.1a131916 #504 npm-pick-manifest@12.0.02b03527 #504 npm-packlist@11.2.05f8ad42 #504 npm-package-arg@14.0.0ee3b96d #504 cacache@21.0.1033f655 #504 @npmcli/run-script@11.0.0ddcc738 #504 @npmcli/promise-spawn@10.0.06a28eb2 #504 @npmcli/package-json@8.0.05879416 #504 @npmcli/installed-package-contents@5.0.041ea727 #504 @npmcli/git@8.0.03fc5fd4 #504 @npmcli/eslint-config@7.0.0 (@owlstronaut)7350ab8 #504 hosted-git-info@10.1.1 (@owlstronaut)c7c7d7f #504 template-oss-apply (@owlstronaut)e9ac85e #501 template-oss-apply (@owlstronaut)e184356 #501 template-oss@5.1.0 (@owlstronaut)644ebb6 #479 template-oss-apply (@owlstronaut)ee64bea #479 @npmcli/template-oss@4.30.0 (@owlstronaut)One column per quarter.
627a7dc #499 avoid ReDoS in addGitSha committish stripping ( @owlstronaut )
627a7dc #499 avoid ReDoS in addGitSha committish stripping (@owlstronaut)790a24b #500 template-oss-apply (#500) (@owlstronaut, test)09cb304 #499 template-oss-apply (@owlstronaut)bea9f84 #499 @npmcli/template-oss@5.1.0 (@owlstronaut)d912f17 #457 expose fetched attestation bundles on manifest ( #457 ) ( @mitchdenny )
d912f17 #457 expose fetched attestation bundles on manifest (#457) (@mitchdenny)586a55d #471 template-oss-apply for new macos images (#471) (@wraithgar)d1cc5c8 #460 template-oss-apply for release branches (#460) (@wraithgar)b741e8b #468 bump @npmcli/template-oss from 4.28.0 to 4.29.0 (#468) (@dependabot[bot], @npm-cli-bot)6912f24 #451 add allowRegistry option ( #451 ) ( @wraithgar )
6912f24 #451 add allowRegistry option (#451) (@wraithgar)ab37bc1 #452 prevent path duplication in attestation URL for registries with … (#452) (@ajayk)ab37bc1 #452 prevent path duplication in attestation URL for registries with (@ajayk)8b8ea3b #454 skip registry key check for keyless (Sigstore/Fulcio) attestations (#454) (@ajayk)8b8ea3b #454 skip registry key check for keyless (Sigstore/Fulcio) attestations (@ajayk)0dfd1cd #456 remove git config from tests (#456) (@wraithgar)96e571a #439 ensure that resolved git ref matches expected sha ( #439 ) ( @klassiker , pacotedev)
96e571a #439 ensure that resolved git ref matches expected sha (#439) (@klassiker, pacotedev)91847c4 #447 fix test for ssri ignoring invalid hashes (#447) (@wraithgar)8f5091d #445 add support for git-256 sha lengths ( #445 ) ( @wraithgar )
db21624 #442 implement gitSubdir according to npa spec ( #442 ) ( @Kakadus )
258e5fd #440 add allowGit option ( #440 ) ( @wraithgar )
`8dc1f22` #436 @npmcli/installed-package-contents@4.0.0
`eed1bd5` #431 @npmcli/git@7.0.0
`32cb6d1` #429 npm-pick-manifest@11.0.1
`aae7798` #428 @npmcli/run-script@10.0.0
aae7798 #428 @npmcli/run-script@10.0.01b233e3 #428 @npmcli/package-json@7.0.0d4b97ec #428 sigstore@4.0.0cf27487 #428 npm-registry-fetch@19.0.03e89235 #428 npm-packlist@10.0.1d46fc27 #428 npm-package-arg@13.0.02a6a9f0 #428 hosted-git-info@9.0.0bbb72cf #428 cacache@20.0.08a642c0 #426 tar@7.4.3 (#426)bun.lockb files are now included in the strict ignore list during packing
bun.lockb files are now included in the strict ignore list during packing844dc08 update node engines to ^20.17.0 || >=22.9.0 (#414) (@wraithgar)2cb6fa7 #415 npm-packlist@10.0.0 (#415)47b928c #412 replace node builtin rmSync with rimraf (#412) (@mbtools)01a126d #466 enable backport mode for v20 ( #466 ) ( @wraithgar )
01a126d #466 enable backport mode for v20 (#466) (@wraithgar)98f72f6 #461 tests should not inherit --ignore-scripts flag from `npm run t… (#422) (@owlstronaut)f8cf9ba #461 @npmcli/template-oss@4.29.0 (@wraithgar)honors ignoreScripts property within options
b7f2691 #465 enable backport mode for v19 ( #465 ) ( @wraithgar )
b7f2691 #465 enable backport mode for v19 (#465) (@wraithgar)ed1aef0 #459 tests should not inherit --ignore-scripts flag from `npm run t… (#422) (@owlstronaut)415e369 #459 @npmcli/template-oss@4.29.0 (@wraithgar)`cbf94e8` #389 prepare script respects scriptshell config (#389) (@milaninfy)
pacote now supports node ^18.17.0 || >=20.5.0
pacote now supports node ^18.17.0 || >=20.5.0f055f71 #395 bump npm-pick-manifest from 9.1.0 to 10.0.0 (#395) (@dependabot[bot])932b9ab #396 bump @npmcli/package-json from 5.2.1 to 6.0.0 (#396) (@dependabot[bot])a1621f9 #397 bump npm-registry-fetch from 17.1.0 to 18.0.0 (#397) (@dependabot[bot])c776199 #398 bump cacache from 18.0.4 to 19.0.0 (#398) (@dependabot[bot])6d59022 #399 bump @npmcli/git from 5.0.8 to 6.0.0 (#399)21ea2d4 #400 bump @npmcli/run-script from 8.1.0 to 9.0.0 (#400)eddbc01 #392 ssri@12.0.06c672e9 #392 proc-log@5.0.003ba2a2 #392 npm-packlist@9.0.02710286 #392 npm-package-arg@12.0.0aa0bd4a #392 @npmcli/promise-spawn@8.0.0df23343 #392 @npmcli/installed-package-contents@3.0.0e4ed5cd #392 bump hosted-git-info ^7.0.0 to ^8.0.0 (@reggi)2871f56 #392 run template-oss-apply (@reggi)39643f1 #382 bump @npmcli/eslint-config from 4.0.5 to 5.0.0 (@dependabot[bot])7e33c82 #383 postinstall for dependabot template-oss PR (@hashtagchris)e4e07bf #383 bump @npmcli/template-oss from 4.23.1 to 4.23.3 (@dependabot[bot])`5e75582` #368 dont set _contentLength if not in headers (#368) (@lukekarrys)
`5fd2c80` #363 linting: no-unused-vars (@lukekarrys)
`5ecce7a` #360 npm-registry-fetch@17.0.0
`116b277` #358 don't strip underscore attributes in .manifest() (#358) (@wraithgar)
`b547e0d` #356 use @npmcli/package-json (#356) (@lukekarrys)
The silent option was used to control whether @npmcli/run-script would write a banner via console.log. Now ouput will be emitted via an process.emit('
silent option was used to control whether @npmcli/run-script would write a banner via console.log. Now ouput will be emitted via an process.emit('output').## 17.0.7 (2024-04-12) ### Dependencies * `e07c3e5` #350 proc-log@4.0.0
`0a5920f` #343 bump sigstore from 2.0.0 to 2.2.0 (#343) (@bdehamer)
`0c96b9e` #338 bug to support rotated keys in signature/attestation audit (#338) (@feelepxyz)
`ace7c28` #305 bump npm-packlist from 7.0.4 to 8.0.0
`c3b892d` #303 bump sigstore from 1.3.0 to 2.0.0
support for node <=16.13 has been removed
Backwards compatibility should be fully implemented but due to the scope of this change it was made a breaking change out of an abundance of caution.
@npmcli/agent. Backwards compatibility should be fully implemented but due to the scope of this change it was made a breaking change out of an abundance of caution.`3307ad9` #278 configurable TUF cache dir (#278) (@bdehamer)
`c99db13` #271 bump minipass from 4.2.7 to 5.0.0
`8f4e39c` #261 always ignore ownership from tar headers (#261) (@nlf)
`2916b72` #259 verifyAttestations to registry.manifest (@feelepxyz, @bdehamer)
`40aa6fe` #253 bump fs-minipass from 2.1.0 to 3.0.0
`a734d61` #250 bump minipass from 3.3.6 to 4.0.0
`dbbda43` #246 @npmcli/run-script@6.0.0
`63797a8` #244 bump @npmcli/promise-spawn from 5.0.0 to 6.0.1
`854fad1` #239 bump @npmcli/promise-spawn from 4.0.0 to 5.0.0
`2a95ddb` #235 bump @npmcli/installed-package-contents
`95f9cd5` handle new npm-package-arg semantics (@wraithgar)
`74821c2` #229 bump @npmcli/run-script from 4.2.1 to 5.0.0
74821c2 #229 bump @npmcli/run-script from 4.2.1 to 5.0.0 (#229)a9844d0 #226 bump @npmcli/promise-spawn from 3.0.0 to 4.0.0 (#226)1058177 #227 bump read-package-json from 5.0.2 to 6.0.00f5ef8a #228 bump @npmcli/installed-package-contents from 1.0.7 to 2.0.07e3b4b5 #220 bump ssri from 9.0.1 to 10.0.04e7536d #222 bump @npmcli/git from 3.0.2 to 4.0.03bc7550 #223 bump npm-pick-manifest from 7.0.2 to 8.0.041fab27 #224 bump proc-log from 2.0.1 to 3.0.04abf24a #218 bump npm-registry-fetch from 13.3.1 to 14.0.0 (#218)this package no longer attempts to change file ownership automatically
`ee16f1f` #207 set as release (@fritzy)
a @npmcli/arborist constructor must be passed in if no tree is provided and pacote is going to operate on git dependencies.
@npmcli/arborist constructor must be passed in if no tree is provided and pacote is going to operate on git dependencies.pacote now has a peer dependency on @npmcli/arborist.
pacote now has a peer dependency on @npmcli/arborist.the _cached attribute has been removed from packuments.
_cached attribute has been removed from packuments.pacote is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0
pacote is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0## 13.6.2 (2022-08-16) ### Bug Fixes * linting
bump @npmcli/run-script from 3.0.3 to 4.1.0
allow reuse of external integrity stream
bump npm-packlist for workspace awareness
pass prefix and workspaces to npm-packlist
add verifySignatures to registry.manifest
## 13.3.0 (2022-05-04) ### Features * add _signatures to manifest
Your coding agent can read these notes before it upgrades. Set up the MCP server →