Skip to content

Update dependency np to v12 - #353

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/np-12.x
Open

Update dependency np to v12#353
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/np-12.x

Conversation

@renovate

@renovate renovate Bot commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
np ^8.0.0^12.0.0 age confidence

Release Notes

sindresorhus/np (np)

v12.0.1

Compare Source

  • Fix npm pack with devEngines.packageManager b0ca868

v12.0.0

Compare Source

Breaking
  • Require Node.js 22, npm 10, pnpm 11 717080a
Improvements

v11.2.2

Compare Source


v11.2.1

Compare Source

  • Skip Node.js engine check for prerelease-to-prerelease bumps abfe30b

v11.2.0

Compare Source


v11.1.0

Compare Source

  • Run Git preflight before prompting (#​788) 8658708
  • Add --dry-run as an alias of --preview d24cb95
  • Run install even with --no-cleanup 2677fcc
  • Fix: Use empty prerelease default for pre-major bump 86a7f26

v11.0.3

Compare Source

  • Fix --release-draft-only failing with version check error 06a142c
  • Fix: Skip missing entry points for lifecycle-built packages (#​782) 6d4b88e

v11.0.2

Compare Source

  • Fix: Allow raising Node.js engine requirement in pre-1.0.0 packages f0859d9

v11.0.1

Compare Source


v11.0.0

Compare Source

Breaking
Improvements
  • Support passkey authentication via automatic browser opening 1ef9af7
  • Support publishing via OIDC authentication (#​772) 3ded31e
  • Add --no-release-notes flag 4f910a2
  • Add --remote flag to specify Git remote 4d5fb6a
  • Add prerequisite check for package entry points 7dcd833
  • Require major version bump when dropping Node.js support 3ed286a
  • Add interactive prerelease identifier selection 6b51dda
  • Support GPG password prompts during version bumping 5a96f80
  • Show unpublished files as warning instead of blocking prompt efcc05e
  • Add npm provenance support d8f3322
  • Add git user configuration check to prevent npm version failures ebb9acf
Fixes
  • Fix --contents flag not being respected when publishing 53904d0
  • Fix compatibility with some external registries c6ef15d
  • Fix repository URL parsing for shorthand and GitHub Enterprise URLs 02b4ed9
  • Fix Yarn Berry detection when packageManager field is missing 7009b77
  • Fix ENOWORKSPACES error when publishing from monorepo workspace 0a8af7b
  • Fix rejection of explicit version numbers ebdcbaa
  • Fix publish hanging indefinitely a651fc4
  • Fix first publish failure for prerelease versions with npm 10+ 3811182
  • Fix subfolder publishing broken since npm 8.5 e996c6f
  • Fix CLI default flags overriding local config values 3804d0b
  • Fix publishConfig handling for access and registry fields 753abb4
  • Fix npm pack JSON parsing when lifecycle scripts output to stdout a13bba2
  • Fix git commands failing with password-protected SSH keys 67b6aff
  • Fix failure with repositories that have multiple initial commits 869f80b
  • Fix package.json config being ignored with global installation 08a3f64
  • Fix long release notes exceeding GitHub URL limit a160aff
  • Fix some network calls never timing out 6a11153
  • Fix contents config option being ignored 88226d7
  • Fix contents option being interpreted as package name 521ecfc
  • Fix incorrect commit range when tags are created out of order fea3eb7
  • Fix getNpmPackageAccess to respect publishConfig.registry 15040c8
  • Fix authentication when publishConfig.registry is official npm registry 380fd24

v10.3.0

Compare Source

  • Auto-run npm login on authentication failure 38abeee
  • Include stderr in error message for failed commands 0ad9a8c
  • Fix rollback not executing when publish fails 005ebdb

v10.2.0

Compare Source


v10.1.0

Compare Source

v10.0.7

Compare Source

  • Allow publishConfig.registry to be npm default registry when using Yarn berry (#​750) 6c5eee3

v10.0.6

Compare Source

v10.0.5

Compare Source

v10.0.4

Compare Source

v10.0.3

Compare Source

v10.0.2

Compare Source

  • Use npm for tagging versions when pnpm is the chosen package manager (#​739) 770418f

v10.0.1

Compare Source

v10.0.0

Compare Source

Breaking
  • Remove the --yarn flag (#​730) 4b3b599
    • The functionality is replaced by --package-manager. See below.
Improvements
  • Add --package-manager flag (#​730) 4b3b599
    • This acts like the packageManager field in package.json. np will default to reading package.json, and look for lockfiles to determine the best package manager as a last resort.
  • Add pnpm support (#​730) 4b3b599

v9.2.0

Compare Source

  • Fix yarn npm publish for scoped packages 8d3a984
  • Fix broken revert code after publish failure 819ed29

v9.1.0

Compare Source

v9.0.0

Compare Source

Breaking
  • Require Node.js 18 and npm 9 6c2e00e
Improvements

v8.0.4

Compare Source

v8.0.3

Compare Source

v8.0.2

Compare Source

  • Fix publish not working with Yarn 3d448c2
  • Include stack trace in errors 12fce88

v8.0.1

Compare Source

  • Fix a crash in the new dependency check beb7db1

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security

socket-security Bot commented Jul 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednp@​8.0.0 ⏵ 12.0.198 +1100100 +195 +14100

View full report

@socket-security

socket-security Bot commented Jul 18, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm execa is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/np@12.0.1npm/execa@9.6.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/execa@9.6.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm powershell-utils is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/np@12.0.1npm/powershell-utils@0.1.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm powershell-utils is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/np@12.0.1npm/powershell-utils@0.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/np-12.x branch 2 times, most recently from 5e4e120 to 0e3e132 Compare July 24, 2026 20:58
@renovate
renovate Bot force-pushed the renovate/np-12.x branch from 0e3e132 to 7e4db35 Compare July 30, 2026 15:44
@renovate
renovate Bot force-pushed the renovate/np-12.x branch from 7e4db35 to 4d45eb0 Compare July 31, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants