install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

install: correct reqBy spec for opt deps - #117

Closed
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11
Closed

install: correct reqBy spec for opt deps#117
larsgw wants to merge 1 commit into
npm:release-nextfrom
larsgw:patch-11

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Return the correct spec for optional dependencies in getRequested.

See https://npm.community/t/242

Return the correct spec for optional dependencies in getRequested.
See https://npm.community/t/242
@larsgw
larsgw requested a review from a team as a code ownerDecember 13, 2018 16:44
@larsgw

Copy link
Copy Markdown
ContributorAuthor

As with #115:

I'm not really sure how to integration-test this without actually cloning git projects at the moment.

Ideas are welcome.

@zkatzkat added semver:patch semver patch level for changes needs-discussion labels Jan 7, 2019
@aeschright

Copy link
Copy Markdown
Contributor

This patch won't resolve the underlying problem -- we actually need to fix what's being put into the package-lock.json so that optional git dependencies are stored using the same format as the others.

@larsgw

Copy link
Copy Markdown
ContributorAuthor

If I remember correctly, that's what this patch is supposed to do (I'll check this afternoon). Or are you suggesting a more general fix?

@larsgw

larsgw commented Jan 8, 2019

Copy link
Copy Markdown
ContributorAuthor

I checked, given this package.json:

{
"name": "060",
"version": "1.0.0",
"optionalDependencies": {
"left-pad": "git+https://github.com/jeffora/left-pad.git#custom-left-pad"
}
}

npm@6.5.0 produces this entry for left-pad:

..."left-pad": {
"version": "1.3.0",
"resolved": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"optional": true
}
...

While my patch produces this:

..."left-pad": {
"version": "git+https://github.com/jeffora/left-pad.git#806c9eda55a3ac4ad365a344ac9024c3ea183f8c",
"from": "git+https://github.com/jeffora/left-pad.git#custom-left-pad",
"optional": true
}
...

The latter works with npm ci, but I can add back the resolved field. However, that's not how dependencies and devDependencies work.

I'll try to add tests (given #115 (comment)) later, but not before my thoughts are confirmed of course.

@iarna

Copy link
Copy Markdown
Contributor

We DO want output like what you quoted, but I'm concerned about your patch for this reason. You wrote this:

return npa.resolve(name, deps[name] || devDeps[name], reqBy.realpath) return npa.resolve(name, deps[name] || devDeps[name] || optDeps[name], reqBy.realpath)

And the thing is, because normalize-package-data (and in turn read-package-json) add all optional deps to regular deps, this patch should be a no-op, because the package metadata we get out of read-package-json will always have all optional deps also included in dependencies.

@iarna

Copy link
Copy Markdown
Contributor

If your patch does fix something, it means something else has gone very wrong somewhere along the way, and we should patch that.

@gurpreetatwal

Copy link
Copy Markdown

Hi all, so I stepped through the code and I believe I have figured out where along the way things went bad. Specifically, it's in the savePackageJson function in install/lib/save.js.

fs.readFile(saveTarget,'utf8',iferr(next,function(packagejson){
constindent=detectIndent(packagejson).indent
constnewline=detectNewline(packagejson)
try{
tree.package=parseJSON(packagejson)
}catch(ex){
returnnext(ex)
}

It replaces tree.package as read by read-package-json with just a fs.readFile of package.json. The in turn breaks that invariant that all optional dependencies should be included in dependencies.

Also the next function eventually invokes saveShrinkWrap as called by exports.saveRequested in lib/install/save.js

I'm not sure what the fix is here as I don't understand the npm code too well, but willing to offer more help if I can get some pointers.

@larsgw

larsgw commented Jan 20, 2019

Copy link
Copy Markdown
ContributorAuthor

It seems the new tree.package from parseJSON isn't passed to anywhere else (apart from saveShrinkwrap of course), so I think it's safe to do this:

letpkgtry{pkg=parseJSON(packagejson)}catch(ex){returnnext(ex)}

As for the tests, I'm not really sure.

@DrSensor

Copy link
Copy Markdown

Hi, I also bump a similar issue but with file:

package-lock.json

{
..."@obot/cli": {
"version": "0.2.1",
"resolved": "/home/wildan/Projects/OSS/bot-byte/packages/cli",
"optional": true,
"requires": {
"@oclif/command": "^1.5.8",
"@oclif/config": "^1.12.0",
"@oclif/errors": "^1.2.2",
"@oclif/plugin-help": "^2.1.4"
},
"dependencies": {...}
},
...
}

package.json

{
..."optionalDependencies": {
"@obot/cli": "file:packages/cli"
}
...
}
$ npm cinpm ERR! cipm can only install packages when your package.json and package-lock.json or npm-shrinkwrap.json are in sync. Please update your lock file with `npm install` before continuing.npm ERR!npm ERR!npm ERR! Invalid: lock file's @obot/cli@0.2.1 does not satisfy @obot/cli@file:packages/clinpm ERR!npm ERR! A complete log of this run can be found in:npm ERR! /home/wildan/.npm/_logs/2019-01-29T09_06_29_704Z-debug.log

DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 29, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
DrSensor added a commit to DrSensor/bot-byte that referenced this pull request Jan 30, 2019
@gurpreetatwal

Copy link
Copy Markdown

@zkat@iarna any thoughts on the above solution? I'd love to help implement, just need some guidance. This same fix also fixes another issue my team is experiencing with package-lock.json and github dependencies. I'm still trying to create a minimal reproduction of that problem, but the code above seems troublesome

@larsgw

Copy link
Copy Markdown
ContributorAuthor

How can I help you?

BTW, another possible solution: save package-lock.json before saving package.json.

@nictownsend

nictownsend commented Feb 18, 2020

Copy link
Copy Markdown

Are there any updates on this? I have optional dependencies that can't currently be pushed to a registry.

antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
🤖 I have created a release *beep* *boop*
---
## [4.0.4](npm/bin-links@v4.0.3...v4.0.4)
(2024-05-04)
### Bug Fixes
*
[`100a4b7`](npm/bin-links@100a4b7)
[npm#117](npm/bin-links#117) linting:
no-unused-vars (@lukekarrys)
### Chores
*
[`e955437`](npm/bin-links@e955437)
[npm#117](npm/bin-links#117) bump
@npmcli/template-oss to 4.22.0 (@lukekarrys)
*
[`b602aca`](npm/bin-links@b602aca)
[npm#117](npm/bin-links#117) postinstall for
dependabot template-oss PR (@lukekarrys)
*
[`955cc34`](npm/bin-links@955cc34)
[npm#116](npm/bin-links#116) bump
@npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 2, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 12, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 8, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@larsgw@aeschright@iarna@gurpreetatwal@DrSensor@nictownsend@zkat