Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Release: npm@6.4.0 - #43

Merged
zkat merged 20 commits into
latestfrom
release-next
Aug 15, 2018
Merged

Release: npm@6.4.0#43
zkat merged 20 commits into
latestfrom
release-next

Conversation

@zkat

@zkatzkat commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

iarnaand others added 14 commits August 1, 2018 20:45
…le (#8)
As discussed on npm.community[1], the fact that
npm registry authentication tokens
cannot be defined using environment variables
does not seem justified anymore.
The restriction is caused by the config loader translating
* all `_` to `-`
* the whole variable name to lowercase
while the credential checker expects a key ending in `:_authToken`.
This change fixes the problem
by having the credential checker try
a key ending in `:-authtoken` after it tried `:_authToken`.
Fixes: https://npm.community/t/233Fixes: npm/npm#15565
PR-URL: #8
Credit: @mkhl
Reviewed-By: @zkat
Remove publish from list of commands not affected by dry-run
PR-URL: #34
Credit: @joebowbeer
Reviewed-By: @zkat
REVERT REVERT, newer versions of this library are broken and print ansi
codes even when disabled.
PR-URL: #39
Credit: @iarna
Reviewed-By: @zkat
`npm audit` currently exits with exit code 1 if any vulnerabilities are found of any level.
Add a flag of `--audit-level` to `npm audit` to allow it to pass if only vulnerabilities below a certain level are found.
Example: `npm audit --audit-level=high` will exit with 0 if only low or moderate level vulns are detected.
Fixes: https://npm.community/t/245
PR-URL: #31
Credit: @lennym
Reviewed-By: @zkat
added a header for usage with process.env to separate section from 'current lifecycle event' and make it easier to find
PR-URL: #14
Credit: @mwarger
Reviewed-By: @zkat
@zkatzkat added the release label Aug 9, 2018
@zkat
zkat requested a review from a team as a code ownerAugust 9, 2018 00:20
Comment threadCHANGELOG.md Outdated

### DOCUMENTATION

* [`c3ab25f3f`](https://github.com/npm/cli/commit/c3ab25f3f54038a813f765845a72ee9f9d836d7d)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is really just a chore and doesn't need to be in the changelog.

Comment threadCHANGELOG.md

### NEW FEATURES

* [`6e9f04b0b`](https://github.com/npm/cli/commit/6e9f04b0baed007169d4e0c341f097cf133debf7)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wow the implementation for that ended up being waaay better than it originally was

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agreeee

@iarna

iarna commented Aug 9, 2018

Copy link
Copy Markdown
Contributor

🐑

@brody2consult

brody2consult commented Aug 9, 2018

Copy link
Copy Markdown

They just published node-gyp@3.8.0 which now uses request@^2.8.7 to resolve the npm audit issues, hope to see this package and other npm dependencies updated in turn.

ref: nodejs/node-gyp#1521

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

@brodybits nice! Thanks for pointing that out! And thanks @rvagg for getting the release out! 🎉 I've updated our dep updates and the changelog. 👍

@zkat

zkat commented Aug 9, 2018

Copy link
Copy Markdown
ContributorAuthor

npm@6.4.0-next.0 has been tagged and released. This PR will stay open until npm@6.4.0 goes live. 👍

@zkat
zkat merged commit 58ece89 into latestAug 15, 2018
isaacs added a commit that referenced this pull request Aug 5, 2019
FEATURES
* [bbcf7b2](npm/hosted-git-info@bbcf7b2)
[#46](npm/hosted-git-info#46)
[#43](npm/hosted-git-info#43)
[#47](npm/hosted-git-info#47)
[#44](npm/hosted-git-info#44) Add support for
GitLab groups and subgroups ([@mterrel](https://github.com/mterrel),
[@isaacs](https://github.com/isaacs),
[@ybiquitous](https://github.com/ybiquitous))
BUGFIXES
* ([3b1d629](npm/hosted-git-info@3b1d629))
[#48](npm/hosted-git-info#48) fix http protocol
using sshurl by default ([@fengmk2](https://github.com/fengmk2))
* [5d4a8d7](npm/hosted-git-info@5d4a8d7) ignore
noCommittish on tarball url generation
([@isaacs](https://github.com/isaacs))
* [1692435](npm/hosted-git-info@1692435) use gist
tarball url that works for anonymous gists
([@isaacs](https://github.com/isaacs))
* [d5cf830](npm/hosted-git-info@d5cf830)
* Do not allow invalid gist urls ([@isaacs](https://github.com/isaacs))
* [e518222](npm/hosted-git-info@e518222)
Use LRU cache to prevent unbounded memory consumption
([@iarna](https://github.com/iarna))
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
Bumps [tap](https://github.com/tapjs/node-tap) from 15.2.3 to 16.0.1.
- [Release notes](https://github.com/tapjs/node-tap/releases)
- [Commits](tapjs/tapjs@v15.2.3...v16.0.1)
---
updated-dependencies:
- dependency-name: tap
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
Jah-yee pushed a commit to Jah-yee/cli that referenced this pull request Apr 16, 2026
…unicode
fix(table): flatten nested objects to dot-notation, safe multi-byte truncation (fixesnpm#40npm#43)
github-actionsBot referenced this pull request in Kevinlee7250/cli Jun 10, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 1, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 7, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Jul 28, 2026
github-actionsBot referenced this pull request in Kevinlee7250/cli Aug 22, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@zkat@iarna@brody2consult@mkhl@joebowbeer@noahbenham@lennym@olore@mwarger