deps: upgrade to npm 11.13.0#456
Conversation
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (45)
📒 Files selected for processing (254)
WalkthroughDocumentation and manpage version bumps to 11.13.0; adds Changes
Sequence Diagram(s)sequenceDiagram
participant User as "User (CLI)"
participant CLI as "npm CLI"
participant Verify as "verify-signatures"
participant Pacote as "pacote.manifest"
participant Output as "JSON output"
User->>CLI: run `npm audit signatures --json --include-attestations`
CLI->>Verify: invoke signature verification (includeAttestations=true)
Verify->>Pacote: request manifest (receive attestationBundles)
Pacote-->>Verify: return manifest + attestationBundles
Verify->>Verify: validate signatures, assemble attestationBundles
Verify->>Output: emit audit results with `verified` array
Output-->>User: JSON with `verified` (DSSE envelopes, verification material, tlog entries)
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested labels
Poem
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@deps/npm/docs/content/using-npm/workspaces.md`:
- Around line 94-96: The fenced command block containing "npm install b -w a" is
missing a language tag; update that code fence to include a shell language
(e.g., add "bash" after the opening backticks) so the block becomes ```
bash
npm install b -w a
``` to satisfy MD040 and enable proper syntax highlighting.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: ee181126-1bdc-4ad6-9398-2fc9a2e3b49e
⛔ Files ignored due to path filters (46)
deps/npm/node_modules/@gar/promise-retry/LICENSEis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/lib/index.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/lib/retry.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/Licenseis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/example/dns.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/example/stop.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/index.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/lib/retry.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/lib/retry_operation.jsis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/node_modules/retry/package.jsonis excluded by!**/node_modules/**deps/npm/node_modules/@gar/promise-retry/package.jsonis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/arborist/build-ideal-tree.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/arborist/isolated-reifier.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/arborist/rebuild.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/arborist/reify.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/audit-report.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/diff.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/inventory.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/isolated-classes.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/node.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/optional-set.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/override-set.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/lib/query-selector-all.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/arborist/package.jsonis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/config/lib/definitions/definitions.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/config/lib/index.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/config/package.jsonis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/run-script/lib/set-path.jsis excluded by!**/node_modules/**deps/npm/node_modules/@npmcli/run-script/package.jsonis excluded by!**/node_modules/**deps/npm/node_modules/@sigstore/core/dist/crypto.jsis excluded by!**/dist/**,!**/node_modules/**deps/npm/node_modules/@sigstore/core/package.jsonis excluded by!**/node_modules/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/envelope.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/events.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/google/api/field_behavior.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/google/protobuf/any.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/google/protobuf/descriptor.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/google/protobuf/timestamp.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/rekor/v2/dsse.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/rekor/v2/entry.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/rekor/v2/hashedrekord.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/rekor/v2/verifier.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/sigstore_bundle.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/sigstore_common.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/sigstore_rekor.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/sigstore_trustroot.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**deps/npm/node_modules/@sigstore/protobuf-specs/dist/__generated__/sigstore_verification.jsis excluded by!**/dist/**,!**/node_modules/**,!**/__generated__/**
📒 Files selected for processing (254)
deps/npm/docs/content/commands/npm-audit.mddeps/npm/docs/content/commands/npm-install-test.mddeps/npm/docs/content/commands/npm-install.mddeps/npm/docs/content/commands/npm-ls.mddeps/npm/docs/content/commands/npm-outdated.mddeps/npm/docs/content/commands/npm-publish.mddeps/npm/docs/content/commands/npm-trust.mddeps/npm/docs/content/commands/npm-update.mddeps/npm/docs/content/commands/npm.mddeps/npm/docs/content/using-npm/config.mddeps/npm/docs/content/using-npm/scripts.mddeps/npm/docs/content/using-npm/workspaces.mddeps/npm/docs/lib/index.jsdeps/npm/docs/output/commands/npm-access.htmldeps/npm/docs/output/commands/npm-adduser.htmldeps/npm/docs/output/commands/npm-audit.htmldeps/npm/docs/output/commands/npm-bugs.htmldeps/npm/docs/output/commands/npm-cache.htmldeps/npm/docs/output/commands/npm-ci.htmldeps/npm/docs/output/commands/npm-completion.htmldeps/npm/docs/output/commands/npm-config.htmldeps/npm/docs/output/commands/npm-dedupe.htmldeps/npm/docs/output/commands/npm-deprecate.htmldeps/npm/docs/output/commands/npm-diff.htmldeps/npm/docs/output/commands/npm-dist-tag.htmldeps/npm/docs/output/commands/npm-docs.htmldeps/npm/docs/output/commands/npm-doctor.htmldeps/npm/docs/output/commands/npm-edit.htmldeps/npm/docs/output/commands/npm-exec.htmldeps/npm/docs/output/commands/npm-explain.htmldeps/npm/docs/output/commands/npm-explore.htmldeps/npm/docs/output/commands/npm-find-dupes.htmldeps/npm/docs/output/commands/npm-fund.htmldeps/npm/docs/output/commands/npm-get.htmldeps/npm/docs/output/commands/npm-help-search.htmldeps/npm/docs/output/commands/npm-help.htmldeps/npm/docs/output/commands/npm-init.htmldeps/npm/docs/output/commands/npm-install-ci-test.htmldeps/npm/docs/output/commands/npm-install-test.htmldeps/npm/docs/output/commands/npm-install.htmldeps/npm/docs/output/commands/npm-link.htmldeps/npm/docs/output/commands/npm-ll.htmldeps/npm/docs/output/commands/npm-login.htmldeps/npm/docs/output/commands/npm-logout.htmldeps/npm/docs/output/commands/npm-ls.htmldeps/npm/docs/output/commands/npm-org.htmldeps/npm/docs/output/commands/npm-outdated.htmldeps/npm/docs/output/commands/npm-owner.htmldeps/npm/docs/output/commands/npm-pack.htmldeps/npm/docs/output/commands/npm-ping.htmldeps/npm/docs/output/commands/npm-pkg.htmldeps/npm/docs/output/commands/npm-prefix.htmldeps/npm/docs/output/commands/npm-profile.htmldeps/npm/docs/output/commands/npm-prune.htmldeps/npm/docs/output/commands/npm-publish.htmldeps/npm/docs/output/commands/npm-query.htmldeps/npm/docs/output/commands/npm-rebuild.htmldeps/npm/docs/output/commands/npm-repo.htmldeps/npm/docs/output/commands/npm-restart.htmldeps/npm/docs/output/commands/npm-root.htmldeps/npm/docs/output/commands/npm-run.htmldeps/npm/docs/output/commands/npm-sbom.htmldeps/npm/docs/output/commands/npm-search.htmldeps/npm/docs/output/commands/npm-set.htmldeps/npm/docs/output/commands/npm-shrinkwrap.htmldeps/npm/docs/output/commands/npm-star.htmldeps/npm/docs/output/commands/npm-stars.htmldeps/npm/docs/output/commands/npm-start.htmldeps/npm/docs/output/commands/npm-stop.htmldeps/npm/docs/output/commands/npm-team.htmldeps/npm/docs/output/commands/npm-test.htmldeps/npm/docs/output/commands/npm-token.htmldeps/npm/docs/output/commands/npm-trust.htmldeps/npm/docs/output/commands/npm-undeprecate.htmldeps/npm/docs/output/commands/npm-uninstall.htmldeps/npm/docs/output/commands/npm-unpublish.htmldeps/npm/docs/output/commands/npm-unstar.htmldeps/npm/docs/output/commands/npm-update.htmldeps/npm/docs/output/commands/npm-version.htmldeps/npm/docs/output/commands/npm-view.htmldeps/npm/docs/output/commands/npm-whoami.htmldeps/npm/docs/output/commands/npm.htmldeps/npm/docs/output/commands/npx.htmldeps/npm/docs/output/configuring-npm/folders.htmldeps/npm/docs/output/configuring-npm/install.htmldeps/npm/docs/output/configuring-npm/npm-global.htmldeps/npm/docs/output/configuring-npm/npm-json.htmldeps/npm/docs/output/configuring-npm/npm-shrinkwrap-json.htmldeps/npm/docs/output/configuring-npm/npmrc.htmldeps/npm/docs/output/configuring-npm/package-json.htmldeps/npm/docs/output/configuring-npm/package-lock-json.htmldeps/npm/docs/output/using-npm/config.htmldeps/npm/docs/output/using-npm/dependency-selectors.htmldeps/npm/docs/output/using-npm/developers.htmldeps/npm/docs/output/using-npm/logging.htmldeps/npm/docs/output/using-npm/orgs.htmldeps/npm/docs/output/using-npm/package-spec.htmldeps/npm/docs/output/using-npm/registry.htmldeps/npm/docs/output/using-npm/removal.htmldeps/npm/docs/output/using-npm/scope.htmldeps/npm/docs/output/using-npm/scripts.htmldeps/npm/docs/output/using-npm/workspaces.htmldeps/npm/lib/arborist-cmd.jsdeps/npm/lib/base-cmd.jsdeps/npm/lib/cli/entry.jsdeps/npm/lib/cli/exit-handler.jsdeps/npm/lib/cli/update-notifier.jsdeps/npm/lib/cli/validate-engines.jsdeps/npm/lib/commands/audit.jsdeps/npm/lib/commands/cache.jsdeps/npm/lib/commands/ci.jsdeps/npm/lib/commands/completion.jsdeps/npm/lib/commands/config.jsdeps/npm/lib/commands/dedupe.jsdeps/npm/lib/commands/diff.jsdeps/npm/lib/commands/dist-tag.jsdeps/npm/lib/commands/doctor.jsdeps/npm/lib/commands/exec.jsdeps/npm/lib/commands/explore.jsdeps/npm/lib/commands/find-dupes.jsdeps/npm/lib/commands/fund.jsdeps/npm/lib/commands/help-search.jsdeps/npm/lib/commands/help.jsdeps/npm/lib/commands/init.jsdeps/npm/lib/commands/install-ci-test.jsdeps/npm/lib/commands/install-test.jsdeps/npm/lib/commands/install.jsdeps/npm/lib/commands/link.jsdeps/npm/lib/commands/ls.jsdeps/npm/lib/commands/org.jsdeps/npm/lib/commands/outdated.jsdeps/npm/lib/commands/pack.jsdeps/npm/lib/commands/pkg.jsdeps/npm/lib/commands/profile.jsdeps/npm/lib/commands/prune.jsdeps/npm/lib/commands/publish.jsdeps/npm/lib/commands/run.jsdeps/npm/lib/commands/sbom.jsdeps/npm/lib/commands/shrinkwrap.jsdeps/npm/lib/commands/team.jsdeps/npm/lib/commands/trust/index.jsdeps/npm/lib/commands/unpublish.jsdeps/npm/lib/commands/update.jsdeps/npm/lib/commands/view.jsdeps/npm/lib/lifecycle-cmd.jsdeps/npm/lib/npm.jsdeps/npm/lib/package-url-cmd.jsdeps/npm/lib/utils/audit-error.jsdeps/npm/lib/utils/auth.jsdeps/npm/lib/utils/cmd-list.jsdeps/npm/lib/utils/error-message.jsdeps/npm/lib/utils/explain-dep.jsdeps/npm/lib/utils/explain-eresolve.jsdeps/npm/lib/utils/format-bytes.jsdeps/npm/lib/utils/format-search-stream.jsdeps/npm/lib/utils/get-identity.jsdeps/npm/lib/utils/log-file.jsdeps/npm/lib/utils/oidc.jsdeps/npm/lib/utils/open-url.jsdeps/npm/lib/utils/ping.jsdeps/npm/lib/utils/queryable.jsdeps/npm/lib/utils/reify-finish.jsdeps/npm/lib/utils/reify-output.jsdeps/npm/lib/utils/update-workspaces.jsdeps/npm/lib/utils/verify-signatures.jsdeps/npm/man/man1/npm-access.1deps/npm/man/man1/npm-adduser.1deps/npm/man/man1/npm-audit.1deps/npm/man/man1/npm-bugs.1deps/npm/man/man1/npm-cache.1deps/npm/man/man1/npm-ci.1deps/npm/man/man1/npm-completion.1deps/npm/man/man1/npm-config.1deps/npm/man/man1/npm-dedupe.1deps/npm/man/man1/npm-deprecate.1deps/npm/man/man1/npm-diff.1deps/npm/man/man1/npm-dist-tag.1deps/npm/man/man1/npm-docs.1deps/npm/man/man1/npm-doctor.1deps/npm/man/man1/npm-edit.1deps/npm/man/man1/npm-exec.1deps/npm/man/man1/npm-explain.1deps/npm/man/man1/npm-explore.1deps/npm/man/man1/npm-find-dupes.1deps/npm/man/man1/npm-fund.1deps/npm/man/man1/npm-get.1deps/npm/man/man1/npm-help-search.1deps/npm/man/man1/npm-help.1deps/npm/man/man1/npm-init.1deps/npm/man/man1/npm-install-ci-test.1deps/npm/man/man1/npm-install-test.1deps/npm/man/man1/npm-install.1deps/npm/man/man1/npm-link.1deps/npm/man/man1/npm-ll.1deps/npm/man/man1/npm-login.1deps/npm/man/man1/npm-logout.1deps/npm/man/man1/npm-ls.1deps/npm/man/man1/npm-org.1deps/npm/man/man1/npm-outdated.1deps/npm/man/man1/npm-owner.1deps/npm/man/man1/npm-pack.1deps/npm/man/man1/npm-ping.1deps/npm/man/man1/npm-pkg.1deps/npm/man/man1/npm-prefix.1deps/npm/man/man1/npm-profile.1deps/npm/man/man1/npm-prune.1deps/npm/man/man1/npm-publish.1deps/npm/man/man1/npm-query.1deps/npm/man/man1/npm-rebuild.1deps/npm/man/man1/npm-repo.1deps/npm/man/man1/npm-restart.1deps/npm/man/man1/npm-root.1deps/npm/man/man1/npm-run.1deps/npm/man/man1/npm-sbom.1deps/npm/man/man1/npm-search.1deps/npm/man/man1/npm-set.1deps/npm/man/man1/npm-shrinkwrap.1deps/npm/man/man1/npm-star.1deps/npm/man/man1/npm-stars.1deps/npm/man/man1/npm-start.1deps/npm/man/man1/npm-stop.1deps/npm/man/man1/npm-team.1deps/npm/man/man1/npm-test.1deps/npm/man/man1/npm-token.1deps/npm/man/man1/npm-trust.1deps/npm/man/man1/npm-undeprecate.1deps/npm/man/man1/npm-uninstall.1deps/npm/man/man1/npm-unpublish.1deps/npm/man/man1/npm-unstar.1deps/npm/man/man1/npm-update.1deps/npm/man/man1/npm-version.1deps/npm/man/man1/npm-view.1deps/npm/man/man1/npm-whoami.1deps/npm/man/man1/npm.1deps/npm/man/man1/npx.1deps/npm/man/man5/folders.5deps/npm/man/man5/install.5deps/npm/man/man5/npm-global.5deps/npm/man/man5/npm-json.5deps/npm/man/man5/npm-shrinkwrap-json.5deps/npm/man/man5/npmrc.5deps/npm/man/man5/package-json.5deps/npm/man/man5/package-lock-json.5deps/npm/man/man7/config.7deps/npm/man/man7/dependency-selectors.7deps/npm/man/man7/developers.7deps/npm/man/man7/logging.7deps/npm/man/man7/orgs.7deps/npm/man/man7/package-spec.7deps/npm/man/man7/registry.7deps/npm/man/man7/removal.7deps/npm/man/man7/scope.7deps/npm/man/man7/scripts.7deps/npm/man/man7/workspaces.7
💤 Files with no reviewable changes (6)
- deps/npm/lib/commands/install-ci-test.js
- deps/npm/lib/commands/install-test.js
- deps/npm/lib/commands/prune.js
- deps/npm/docs/content/using-npm/scripts.md
- deps/npm/docs/content/commands/npm-trust.md
- deps/npm/lib/commands/find-dupes.js
PR-URL: nodejs/node#62216 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> PR-URL: #456 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
PR-URL: nodejs/node#62448 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: #456 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
PR-URL: nodejs/node#62898 Reviewed-By: Jordan Harband <ljharb@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Santiago Gimeno <santiago.gimeno@gmail.com> PR-URL: #456 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
f7ec1a9 to
ed501c7
Compare
PR-URL: nodejs/node#62898 Reviewed-By: Jordan Harband <ljharb@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Santiago Gimeno <santiago.gimeno@gmail.com> PR-URL: #456 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Summary by CodeRabbit
New Features
Documentation