install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

install: fix install checks for optional/dev dependencies - #76

Closed
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4
Closed

install: fix install checks for optional/dev dependencies#76
larsgw wants to merge 6 commits into
npm:release-nextfrom
larsgw:patch-4

Conversation

@larsgw

Copy link
Copy Markdown
Contributor

Problem: when a sub-dependency is required by an optional dependency in two different ways (e.g. once directly and once via another sub-dependency) the sub-dependency checking process ends up at the (optional) parent dependency twice, always failing the check.

Fix: make sure that the tracking of already seen packages has no effects on parallel paths.

See https://npm.community/t/2569

@larsgw
larsgw requested a review from a team as a code ownerOctober 8, 2018 14:00
@larsgwlarsgw changed the title install: fix install checks for optional dependenciesinstall: fix install checks for optional/dev dependenciesOct 8, 2018
@zkat

zkat commented Nov 13, 2018

Copy link
Copy Markdown
Contributor

I'd like to get a review from @iarna on this one.

@surmacz

Copy link
Copy Markdown

In which version this this fix is going to be released?

@mramato

Copy link
Copy Markdown

I'm not one for "me-too" posts, but I was extremely disappointed to see this didn't go into npm 6.5.0. It's preventing me and my team from making effective use of package-lock.json or submitting it to our source control.

Is there anything the community can do to help move this patch along? As an OSS maintainer, I completely understand that things can sometimes fall through the cracks when it comes to waiting for someone to review them, but this seems like a fairly minimal, high-impact change to the source.

@iarna

Copy link
Copy Markdown
Contributor

This was merged as 1342071 and will be in the next release of npm (which will be the first or second week of January, schedules depending).

I rewrote the test to be a bit more in our current style and take advantage of our test tooling. You can see the changes here:

https://gist.github.com/iarna/ca94b7b044cd55c95753964aad27e4d2

@rooby

Copy link
Copy Markdown

None of the recent release notes seem to have a link to this pull request. Did it make it into 6.6.0 or 6.7.0?

Was it this one in 6.6?

1342071 npm.community#2569 Fix checking for optional dependencies. (@larsgw)

@andersk

Copy link
Copy Markdown
Contributor

@rooby Yes, see the previous comment.

@khitrenovich

Copy link
Copy Markdown

Is there any chance that npm v6.6 will be bundled with the next Node v10.x release? Say, v10.16...

@larsgw

Copy link
Copy Markdown
ContributorAuthor

@khitrenovich it's being worked on: nodejs/node#25804

zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
zypA13510 added a commit to zypA13510/ui5-fontawesome that referenced this pull request Jun 7, 2019
This would avoid generating excessive package-lock.json commits (fixed in npm/cli#76).
lkiesow added a commit to lkiesow/opencast that referenced this pull request Jun 19, 2019
This patch updates node and npm to the latest LTS version which [should
hopefully fix the package-lock.json problem](npm/cli#76 (comment))
although this is hard to verify.
Worst case, we just upgraded npm.
larsgw added a commit to larsgw/cli that referenced this pull request Jul 1, 2019
Instead of creating a new set each time a new node gets visited, so that its siblings do not have it in `seen`, just remove the node from the original set right after all child nodes are visited.
See npm#76
isaacs pushed a commit that referenced this pull request Jul 2, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
isaacs pushed a commit that referenced this pull request Jul 3, 2019
Instead of creating a new set each time a new node gets visited, so that
its siblings do not have it in `seen`, just remove the node from the
original set right after all child nodes are visited.
See #76
Credit: @larsgw
PR-URL: #206Close: #206
Reviewed-by: @isaacs
antongolub pushed a commit to antongolub-forks/npm-cli that referenced this pull request May 18, 2024
* chore: bump @npmcli/template-oss from 4.12.0 to 4.12.1
Bumps [@npmcli/template-oss](https://github.com/npm/template-oss) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/npm/template-oss/releases)
- [Changelog](https://github.com/npm/template-oss/blob/main/CHANGELOG.md)
- [Commits](npm/template-oss@v4.12.0...v4.12.1)
---
updated-dependencies:
- dependency-name: "@npmcli/template-oss"
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: postinstall for dependabot template-oss PR
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: npm CLI robot <npm-cli+bot@github.com>
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 1, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Jul 10, 2026
github-actionsBot added a commit to Kevinlee7250/cli that referenced this pull request Aug 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:patchsemver patch level for changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants

@larsgw@zkat@surmacz@mramato@iarna@rooby@andersk@khitrenovich@lucasfeliciano@feelepxyz