-
Notifications
You must be signed in to change notification settings - Fork 4.1k
chore: release 11.8.0 #8853
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: release 11.8.0 #8853
Conversation
Release ManagerRelease workflow run: https://github.com/npm/cli/actions/runs/21217988436 Release Checklist for v11.8.0
|
6392e59 to
75e0476
Compare
0361e85 to
3eae5ff
Compare
|
Would really be appreciated if this release is out asap. Since Saturday version 11.7.0 is being blocked by Xray (CVE-2026-23745). |
But does it fix the mentioned vulnerability? I do not see version update in package-lock files. |
Just checked - you´re right. 11.8.0 still uses tar version 7.5.2 - needs to be ^7.5.3 |
You're right, also with diff dependencies. Just reported to #8911 |
This comment was marked as off-topic.
This comment was marked as off-topic.
3eae5ff to
cc0bb48
Compare
cc0bb48 to
bda624e
Compare
This comment was marked as off-topic.
This comment was marked as off-topic.
|
🤖 Created releases: 🌻 |
|
🤖 Created releases:
🌻 |
Release Workflow
🚨🚨🚨 @npm/cli-team: The post-release workflow failed for this release. Manual steps may need to be taken after examining the workflow output. 🚨🚨🚨 |
🤖 I have created a release beep boop
11.8.0
11.8.0 (2026-01-21)
Features
545e861#8828 show proxy environment variables in npm config list (Max Black)Bug Fixes
c2f784d#8859 preserve serialNumber UUID in CycloneDX SBOM output [BUG] sbom cyclonedx files contain invalid serialNumber #8837 (fix: preserve serialNumber UUID in CycloneDX SBOM output #8837 #8859) (@saksham-malhotra-27)f2c3af7#8840 more intuitive byte formatting boundaries for rounding (fix: more intuitive byte formatting boundaries for rounding #8840) (@watilde)Documentation
3474ec3#8866 fix typo/logic error in npm-dedupe docs (docs: fix typo/logic error in npm-dedupe docs #8866) (@Schweinepriester)5552e46#8797 npm-install: explain package-lock.json behavior (docs(npm-install): explain package-lock.json behavior #8797) (@MaxBlack-dev, Max Black)Dependencies
f478ca0#8919postcss-selector-parser@7.1.12b6a71f#8919path-scurry@2.0.119096f2#8919sigstore@4.1.0e7f5d1e#8919lru-cache@11.2.49e756ae#8919ip-address@10.1.0f951820#8919common-ancestor-path@2.0.07a949ad#8919@sigstore/verify@3.1.06979ce1#8919@sigstore/sign@4.1.0b4a6a41#8919@sigstore/core@3.1.0dc8a8e8#8919@sigstore/tuf@4.0.1be221ea#8919validate-npm-package-name@7.0.2149823d#8919diff@8.0.332b2001#8919tar@7.5.4Chores
8f599df#8919 pin jsdom to 27.0.0 (@wraithgar)f4f1161#8919 dev dependency updates (@wraithgar)@npmcli/arborist@9.1.10@npmcli/config@10.5.0libnpmdiff@8.0.13libnpmexec@10.1.12libnpmfund@7.0.13libnpmpack@9.0.13arborist: 9.1.10
9.1.10 (2026-01-21)
Dependencies
f951820#8919common-ancestor-path@2.0.0config: 10.5.0
10.5.0 (2026-01-21)
Features
5a444d5#8828 export environment config variable names (Max Black)libnpmdiff: 8.0.13
Dependencies
@npmcli/arborist@9.1.10libnpmexec: 10.1.12
Dependencies
@npmcli/arborist@9.1.10libnpmfund: 7.0.13
Dependencies
@npmcli/arborist@9.1.10libnpmpack: 9.0.13
Dependencies
@npmcli/arborist@9.1.10This PR was generated with Release Please. See documentation.