Framework: Update npm to v12 - #82732
Draft
manzoorwanijk wants to merge 1 commit into
Draft
manzoorwanijk wants to merge 1 commit into
manzoorwanijk wants to merge 1 commit into
Conversation
🤖 PR meta 🤖🏷️ LabelsThis pull request needs exactly one label indicating its type, and has 0.
Read more about Type labels in Gutenberg. If you cannot add labels yourself, a reviewer can do it for you. 📦 Bundle sizeSize Change: 0 B Total Size: 8.25 MB
⚡ PerformanceShow the resultsClient side metrics exclude the server response time. front-end-block-theme
front-end-classic-theme
media-processing
media-upload
post-editor
site-editor
|
manzoorwanijk
force-pushed
the
update/npm-12
branch
from
September 10, 2026 12:34
48ff320 to
19c2e92
Compare
This was referenced Sep 11, 2026
manzoorwanijk
force-pushed
the
update/npm-12
branch
3 times, most recently
from
September 14, 2026 09:59
ad5c010 to
0c93e6d
Compare
manzoorwanijk
force-pushed
the
update/npm-12
branch
2 times, most recently
from
September 22, 2026 07:39
ea5cbf6 to
3815ba1
Compare
manzoorwanijk
force-pushed
the
update/npm-12
branch
2 times, most recently
from
September 29, 2026 08:20
b8bc152 to
d109772
Compare
manzoorwanijk
force-pushed
the
update/npm-12
branch
from
October 1, 2026 11:15
8734714 to
c7cf7a3
Compare
manzoorwanijk
commented
Oct 2, 2026
| "core-js": false, | ||
| "core-js-pure": false, | ||
| "esbuild": false, | ||
| "file:packages/icons": true, |
Member
Author
There was a problem hiding this comment.
This file:packages/icons here is a temporary workaround for a bug in npm CLI, which is being fixed in npm/cli#9990
manzoorwanijk
force-pushed
the
update/npm-12
branch
from
October 2, 2026 03:44
122cee6 to
08de4c8
Compare
This was referenced Oct 2, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to the supply chain policy the new major requires. Install scripts are now opt-in, so record every dependency that ships one in allowScripts, all denied: nothing compiles on install. npm 12 does not exempt workspace lifecycle scripts from allowScripts under install-strategy=linked, so @wordpress/icons needs an entry of its own to keep generating src/library on install. See npm/cli#9982. Closes #82328. Supersedes #82689.
manzoorwanijk
force-pushed
the
update/npm-12
branch
from
October 2, 2026 06:11
c880581 to
5fdb2d7
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What?
Closes #82328
Closes #74877
Supersedes #82689
Moves the repository to npm v12 and records the supply chain policy the new major requires.
Why?
npm v12 is a security release: dependency install scripts, git dependencies and remote URL dependencies all become opt-in. The Node.js Release WG will not bundle it on Node.js 22, 24 or 26, so waiting costs another year with the protections off.
How?
devEngines.packageManager.versionis the single source of truth since #82235, so CI and the release tooling pick up>=12.0.2from the one-line bump.allowScriptsdenies every dependency that ships an install script, so nothing compiles on install..npmrcaddsstrict-allow-scripts, so an unlisted script fails the install rather than being skipped silently, and refuses local tarballs.@wordpress/iconsis the one approval. npm 12 does not exempt workspace lifecycle scripts fromallowScriptsunderinstall-strategy=linked(npm/cli#9982), so without itsrc/librarynever generates on install.Testing Instructions
npm install --global npm@12.node_modules, thennpm ci. The lockfile should be unchanged andpackages/icons/src/librarypopulated.package.json):npm install --dry-run --no-save github:sindresorhus/is-odd npm install --dry-run --no-save https://registry.npmjs.org/is-odd/-/is-odd-3.0.1.tgz npm pkg delete allowScripts.esbuild && npm install --dry-run git checkout package.jsonTesting Instructions for Keyboard
N/A, no user interface change.
Use of AI Tools
Claude Code drafted and verified the changes against clean installs. I reviewed them.