[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[pull] latest from npm:latest - #139

Merged
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest
Feb 25, 2026
Merged

[pull] latest from npm:latest#139
pull[bot] merged 19 commits into
LadyK-21:latestfrom
npm:latest

Conversation

@pull

@pullpullBot commented Feb 25, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Michael Smithand others added 19 commits February 24, 2026 12:30
This pull request adds support for CircleCI as a provider of OpenID
Connect (OIDC) tokens in CI environments, alongside existing support for
GitHub Actions and GitLab. The implementation includes both code changes
to detect and handle CircleCI OIDC tokens and new tests to ensure
correct behavior.
## Usage
In your `.circleci/config.yml`:
```yaml
version: 2.1
jobs:
publish:
docker:
- image: cimg/node:lts
steps:
- checkout
- run:
name: Publish to npm
command: |
NPM_AUDIENCE="npm:$(npm config get registry | sed 's|https\?://||;s|/$||')"
NPM_ID_TOKEN=$(circleci run oidc get --claims "{\"aud\": \"$NPM_AUDIENCE\"}")
npm publish
workflows:
publish:
jobs:
- publish
```
Note: Unlike GitHub Actions and GitLab, CircleCI requires manually
fetching the OIDC token with the correct audience claim using the
`circleci` CLI.
This pull request adds support for CircleCI as a trusted provider in the
trust command system. The changes introduce a new `circleci` subcommand,
implement its logic for validating and processing CircleCI-specific
trust relationships, and update documentation and tests to reflect the
new functionality.
Fixes#8892
Older packages on the registry use the deprecated `licenses` array
(`"licenses": [{"type": "MIT", ...}]`) instead of the singular `license`
string. `npm sbom` only checked for `license`, so these packages all
showed up as `NOASSERTION`.
This checks for the `licenses` array as a fallback in both the SPDX and
CycloneDX codepaths. When there are multiple entries they're joined with
` OR `.
Also noticed the CycloneDX expression branch was referencing
`node.package.license` directly instead of the already-computed
variable, which would break for these legacy packages. Fixed that too.
)
Continuing the `install-strategy=linked` fixes from #8996. While testing
on the [Gutenberg
monorepo](WordPress/gutenberg#75814), `esbuild`
installs fail because its postinstall script runs twice in parallel
against the same store directory.
## Summary
With `install-strategy=linked`, postinstall scripts run twice for every
store package — once for the store entry and once for its symlink. For
packages like `esbuild` whose postinstall modifies files in-place
(`fs.linkSync` to replace the JS wrapper with a native binary), this
race condition corrupts the install.
## Root cause
In `rebuild.js`, `#runScripts` destructures `isStoreLink` from
`node.target` (the store entry) to decide whether to skip a node. But
`isStoreLink` is a property of the link node itself (`node`), not its
target. Store entries don't have `isStoreLink`, so it's always
`undefined` and the guard never triggers. Both the store entry and the
store link run scripts against the same directory in parallel.
## Changes
- Fixed the skip condition in `rebuild.js` `#runScripts` to use
`node.isLink && node.target?.isInStore` instead of reading `isStoreLink`
from `node.target`. This correctly skips store links (symlinks pointing
to store entries) while still allowing workspace links and store entries
themselves to run scripts.
- Added a regression test that verifies postinstall scripts run exactly
once for store packages.
## References
Fixes#9012
npm audit signatures fails when a registry only uses keyless
(Sigstore/Fulcio) attestations and doesn't provide registry signing
keys. The[ auditedWithKeysCount guard in verify-signatures.js
](https://github.com/npm/cli/blob/latest/lib/utils/verify-signatures.js#L48)
treats any registry without keys as unsupported, even though keyless
attestations don't need registry keys at all -- the signing certificate
is embedded directly in the bundle and verified through Sigstore's TUF
root of trust.
This updates the check to also accept verified keyless attestations as a
valid audit result, so registries that exclusively use Fulcio-based
signing (like Chainguard) work correctly with npm audit signatures.
Before this change:
npm error found no dependencies to audit that were installed from a
supported registry
After:
audited 1 package in 1s
1 package has a verified attestation
This change works together with the corresponding pacote fixes
([pacote/pull/454](npm/pacote#454))
([pacote/pull/452](npm/pacote#452))
which allows keyless attestation bundles to pass the registry key
matching check.
@pullpullBot locked and limited conversation to collaborators Feb 25, 2026
@pull
pullBot merged commit 4426411 into LadyK-21:latestFeb 25, 2026
14 of 16 checks passed
@LadyK-21

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

StatusScanner Critical High Medium LowTotal (0)
🔚Open Source Security0000 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@LadyK-21@wraithgar@JNC4@manzoorwanijk@ajayk