Skip to content

[pull] latest from npm:latest - #180

Merged
pull[bot] merged 3 commits into
adamlaska:latestfrom
npm:latest
May 20, 2026
Merged

[pull] latest from npm:latest#180
pull[bot] merged 3 commits into
adamlaska:latestfrom
npm:latest

Conversation

@pull

@pull pull Bot commented May 20, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

reggi and others added 3 commits May 20, 2026 12:20
## Summary

Adds permission flags to trust create operations. Users must now specify
at least one of `--allow-publish` or `--allow-stage-publish` (alias:
`--allow-staged-publish`) when creating trust configurations.

## Changes

- Add `--allow-publish` and `--allow-stage-publish` flags to all trust
provider commands (GitHub, GitLab, CircleCI)
- Require at least one permission flag when creating trust
configurations
- Include permissions in the request body and display output
- Add `PERMISSIONS` constants for permission values
- Update tests and completion snapshots for new flags

## Related

- #9201

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
When the user has `min-release-age=N` in their `.npmrc`, the config flatten
function derives a `before` date used by pacote. Whenever pacote spawns a
child npm process (e.g. preparing a `git:` or `github:` dep), it forwards
`--before=<date>` to the child. The child then loads the same `.npmrc` and
the previously declared mutual-exclusivity between `before` and
`min-release-age` caused a hard configuration error.

This makes the two options coexist: the `exclusive` constraints are
removed and both flatten functions resolve to the earlier of the two
effective dates, never widening the user's most conservative bound.
The `min-release-age` flatten no longer mutates the per-source config
object (the prior `obj.before = ...` / `delete obj['min-release-age']`
mutations were vestigial and only masked the conflict at the parent
level, not in spawned children).

`min-release-age` is also added to the `params` arrays for `outdated`
and `update` so it remains visible in their command help; it was
previously displayed implicitly via the `before` exclusive grouping.

Fixes: #9291
@pull pull Bot locked and limited conversation to collaborators May 20, 2026
@pull pull Bot added the ⤵️ pull label May 20, 2026
@pull
pull Bot merged commit 18ebb0f into adamlaska:latest May 20, 2026
0 of 3 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants