`pnpm unpublish` sent every registry mutation without `npm-auth-type` and
turned any 401 into ERR_PNPM_UNAUTHORIZED, so an account with 2FA
enforced could never unpublish even though it was logged in: the registry
answered with an OTP challenge the command did not recognize.
Both stacks now run the packument PUT and every tarball/packument DELETE
through the shared OTP session: the first attempt carries a configured
`--otp` (under `npm-auth-type: legacy`), otherwise `npm-auth-type: web`
requests the web-based challenge; a 401 whose body carries
`authUrl`/`doneUrl` starts the browser flow, one mentioning the classic
"one-time pass" wording prompts for a code, and the obtained password is
reused by the remaining requests of the run. Any other 401 stays a plain
authentication failure, now including the registry's body.
The 401-body classification that `dist-tag` and `setDistTag` each carried
privately moves to the web-auth packages
(`SyntheticOtpError.fromUnauthorizedBody` in TypeScript,
`otp_challenge_from_unauthorized_body` in Rust) so all call sites share
it. The Rust unpublish command becomes generic over the web-auth host so
its unit tests can script the challenge flow against a mocked registry.
Closespnpm/pnpm#14464
A test's options object is the entire input to the subject under test, so a
key nothing reads does not fail: it quietly runs the default instead of the
case the test is named for. Both install helpers accepted anything — the
headless one took `opts?: any`, and the install one takes `opts?: T & {...}`,
where an unknown key is absorbed into the inferred `T`. That is how the
`registries` -> `registriesByScope` rename left seven suites pointed at the
wrong registry with a green type-check, and only CI to say so.
The headless helper now takes a `Partial<HeadlessOptions>`. Everything that
surfaced was real:
- Seven fields `HeadlessOptions` requires and reads — `configByUri`,
`globalVirtualStoreDir`, `pruneStore`, `sideEffectsCacheRead`/`Write`,
`userAgent`, `virtualStoreDirMaxLength` — were never set, so every headless
test ran with them `undefined`. They now carry the values the install
behaved as.
- `verifyStoreIntegrity` is a package-store option, not a headless one. The
three tests that "disable" it were setting a key nobody read; it is now
forwarded to the store.
- `hoistPattern: '*'` and `publicHoistPattern: '*'` are `string[]`. A
one-character string iterates like a one-element array, which is the only
reason they worked.
- `development`, `optional`, `production` predate `include`, which the same
calls already set, and `sideEffectsCache` predates the read/write split.
Constraining the install helper's `T` is a bigger job — 162 errors, mostly
unrelated to options keys — so it keeps its generic and gains a narrow guard
instead: the three renamed keys are declared with a literal type that names
the replacement. It caught one more live case on the way in.
Registries do not all lay out tarball URLs the way the npm registry does.
JFrog Artifactory repeats the scope in a scoped package's tarball filename
(`@acme/widget/-/@acme/widget-1.0.0.tgz`) where npm strips it. pnpm cannot
rebuild such a URL, so it writes it out for every scoped package instead of
omitting it, and the lockfile carries a host-specific URL per dependency.
pnpm had no place to record such a fact, because it had no place to
describe a registry at all — only three ways to name one. `registries`
mapped a scope to a URL, `namedRegistries` mapped a bare-specifier prefix
to a URL, and neither could carry anything else.
`registries` now declares a registry once, keyed by its URL, with every
fact about it in the entry: a `serverType`, the `scopes` routed to it,
and the `prefix` it answers to. `serverType` has three states:
undeclared strict; only the exact canonical URL is reconstructible
npm also serves the percent-encoded scoped path
artifactory repeats the scope in the tarball filename
registry.npmjs.org resolves to `npm` as a built-in, so its behavior is
unchanged and the old hostname check becomes that one default rather than a
special case in the predicate. `npm` cannot be the default: asserting
npmjs-compatibility is a claim only the operator can make.
The URL is the key because every fact in an entry is a fact about that
server. Keying the layout by scope would bind it to whoever the scope
currently points at, so two developers whose scope resolves differently
would write lockfiles that disagree about which URLs may be omitted.
`scopes` and `prefix` are routes to the registry and are inverted at
config-read time into the two lookups the rest of pnpm already queries,
leaving the resolver, installer, and lockfile layers untouched and the
precedence chain (builtin < .npmrc < yaml < `_auth` < CLI) unchanged.
The layout is declared, never inferred. Sniffing the registry URL cannot work:
a virtual repository serves both layouts at once, depending on whether each
package was synced from upstream or published locally, so no registry-level
signal — route, response header, or probe — decides it. Declaring it also
keeps a wrong guess a fixable misconfiguration instead of a silent breakage.
`serverType` feeds a single URL builder that both sides of the lockfile use:
the writer omits a tarball URL only when the builder reproduces it, and the
reader rebuilds it with the same call. They therefore agree by construction,
so pnpm never has to assume a registry serves some second URL as well.
The setting lives in pnpm-workspace.yaml rather than .npmrc because the
lockfile depends on it: one developer omitting URLs that another reconstructs
differently would break a frozen install. A `serverType` in the global
config.yaml is ignored for the same reason, while the routes declared
alongside it are kept. Credentials are rejected there — the file is
committed — and still belong in .npmrc. The registry URL is the map key, so
the request-destination env gate applies to keys as well as values.
Credentials and unknown fields are refused after parsing, since a parse
error renders the offending source line verbatim.
A map whose values are all strings is the older `<scope>: <url>` shape and
is still read as one. Mixing the two shapes in one map is refused, and so is
a URL-keyed entry written as a string. `namedRegistries` is deprecated in
favor of `prefix` and is read only for prefixes `registries` does not
declare; a prefix stays singular because it is the registry's identity in a
lockfile dep path.
An entry that routes nothing to itself and matches no configured registry is
reported as a warning rather than silently ignored; it is a warning and not
an error because a shared config dependency can legitimately describe
registries a given project does not use.
Config dependencies and pnpr-server-mode resolution pass no server type; in
both, the writer and the reader share that default, so they stay consistent.
Closespnpm/get-npm-tarball-url#16. Supersedes pnpm/pnpm#13920.
Remove the legacy repository changelog files now that release changelog storage defaults to the registry. The publish path composes and injects CHANGELOG.md into release tarballs, so keeping historical copies in source control duplicates generated release data.
Update adm-zip to the patched 0.6 release and override vulnerable transitive versions after the dependency audit began rejecting versions below 0.6.0.
`pacquet add <name>` without a version and `pacquet update --latest`
fetched the raw `latest` dist-tag, so with an active
`minimumReleaseAge` they could write a range into `package.json` that
the follow-up install rejects (related to pnpm/pnpm#11165).
Resolve the tag through the same package-picking path as install. The
maturity filter repoints `latest` to the newest mature version, keeping
the manifest and lockfile consistent and matching the TypeScript CLI.
Share one lazily constructed `LatestPicker` across every selector in a
command. This preserves command-validation and unmatched-selector error
ordering while reusing the policy, metadata cache, fetch locker, and
registries map. Report invalid `minimumReleaseAgeExclude` values with
`ERR_PNPM_INVALID_MINIMUM_RELEASE_AGE_EXCLUDE`, matching install and the
TypeScript CLI.
Add TypeScript and Rust regression coverage for bare update, update
with `--latest`, and add without a version.
---------
Co-authored-by: Manuel Pelloni <manuel.pelloni@m4ss.net>
* fix(pnpr): route the registry mock by exact name and restore its write ACL
The full-purity registry-mock config (pnpm/pnpm#12747) broke the TypeScript
test suite in ways TS CI never caught (it was path-filter-skipped on that
pnpr-only merge):
- The @zkochan/* and @pnpm/* routes claimed those entire REAL npm scopes
with no fall-through, 404ing real packages that proxied dependency trees
need (@zkochan/async-regex-replace, @pnpm/error). The fixture packages in
those scopes are now routed individually; the rest of each scope proxies
npm again.
- Unscoped names tests publish to the mock (test-publish-*, batch-*,
project-100, ...) routed to the npmjs upstream, where a write is
rejected. They are enumerated exactly; @pnpmtest/* covers
dynamically-suffixed publish tests. Deliberately no unscoped prefix
wildcards: a test-* route would swallow real packages like test-exclude
(istanbul's dependency tree).
- The migration dropped the '**' ACL entry, and the built-in default
admits no one to unpublish, so unpublish tests got 403. Restored:
$all access, $authenticated publish and unpublish.
* test(pnpm11): stop dist-tagging and publishing over real npm packages
Under the mounts model a write to an upstream-routed name is rejected, and
the old materialize-on-write overlay is gone on purpose — so tests may only
write to packages the mock hosts. Migrate every real-npm write target to a
dedicated fixture:
- @pnpm.e2e/multi-version-{a,b,c} replace is-negative/is-positive/micromatch
in the update, overwrite, and interactive-update tests.
- @pnpm.e2e/circular-{iterator,ext,symbol} replace the
es6-iterator/es5-ext/es6-symbol circular trio; circular-ext requires
^2.0.1 so both circular-iterator versions land in the tree, which is the
point of the concurrency test.
- @pnpm.e2e/function-with-clone replaces lodash where the test executes the
installed code (module and module.clone are functions).
- @scoped/exports-function replaces @rstacruz/tap-spec in the scoped
devDependencies-save test.
- @pnpm.e2e/has-build-metadata{,-dep} replace @monorepolint/{core,cli}: the
dependency range carries build metadata (^0.5.0-alpha.51+f10fea0), which
is what pnpm/pnpm#2928 is about; the hardcoded real-npm integrity becomes
getIntegrity().
- The search tests query a hosted fixture (search scans hosted stores only).
- Dynamically-suffixed publish names move into the @pnpmtest scope, since
exact routes cannot cover generated names.
- The vestigial addDistTag('foo') calls in the workspace-protocol tests are
dropped; those resolve via workspace:, never the registry.
Read-only usages of real npm packages are untouched — they keep proxying.
getIntegrity() in the registry-mock helper also learns the proxy cache's
post-mounts layout (.pnpr-cache/~public/<digest>/), which the patch tests
depend on for proxied is-positive.
* fix(registry-mock): re-enumerate proxy-cache namespaces on every getIntegrity retry
The ~public namespace directory is created lazily together with the first
cached packument, so a candidate list built once before the retry loop could
never discover a namespace that appears while the retries are running.
* fix(pnpr): align Config::proxy routing with the bundled registry-mock config
Route the @pnpm and @zkochan fixture packages by exact name in
REGISTRY_MOCK_LOCAL_PATTERNS too, so pacquet's in-process test registry
proxies the rest of those real npm scopes exactly like the bundled
config.yaml does. Also filter the getIntegrity() proxy-cache namespace
enumeration to directories, so a stray file under ~public/ cannot turn a
retryable miss into an ENOTDIR error.
pnpr no longer accepts HTTP Basic (`_auth`) on requests, so test helpers
that authenticated with Basic credentials started returning 401 once CI
ran against a bearer-only pnpr build.
Switch the registry-mock `addDistTag` helper and the
publish/deprecate/dist-tag/unpublish suites to the bearer token that the
with-registry globalSetup already mints (`REGISTRY_MOCK_TOKEN`), exposed
through a new `getRegistryMockToken()` helper.
The two install/auth.ts tests that cover pnpm's own Basic `_auth` client
support now run against a small local registry proxy that enforces Basic
auth and forwards to pnpr with a bearer token, so that coverage is kept.
The TypeScript pnpm CLI freezes at v11; pnpm 12 will be the Rust pacquet
port. To make that split legible, all TypeScript source, test, and build
directories move under a new top-level pnpm11/ directory. The name states
the version boundary rather than implying a behavioral fork, since the two
stacks are meant to behave identically.
Scope is source-only: the shared workspace root stays at the repo root.
pnpm-workspace.yaml, package.json, pnpm-lock.yaml, .pnpmfile.cjs,
.meta-updater, __patches__, .changeset, .husky, and the lint/spell configs
remain in place, so one pnpm workspace and one Cargo workspace still span
all three products. pnpr/client and pacquet/tasks/registry-mock stay as
cross-product workspace members.
Rewiring the move required:
- pnpm-workspace.yaml globs prefixed with pnpm11/
- root package.json script paths, eslint.config.mjs, tsconfig.lint.json,
.gitignore, and CODEOWNERS updated
- .meta-updater/src/index.ts literals repointed (pnpm11/pnpm/package.json,
pnpm11/__utils__, pnpm11/__typings__, and the main package directory)
- regenerated every moved package's repository/homepage URL via meta-updater
- pnpm11/pnpm/bundle-deps.ts and __utils__/scripts/src/typecheck-only.ts
climb one more level to reach the repo root
.meta-updater stays at the repo root because @pnpm/meta-updater resolves
its config at <cwd>/.meta-updater/main.mjs.
TS CI (.github/workflows/ci.yml) now only runs when pnpm11/-relevant paths
change, via a dorny/paths-filter changes job plus a TS CI / Success
aggregate gate; branch protection should require only that gate.