Skip to content

Framework: Update npm to v12 - #82732

Draft
manzoorwanijk wants to merge 1 commit into
trunkfrom
update/npm-12
Draft

manzoorwanijk wants to merge 1 commit into
trunkfrom
update/npm-12

Conversation

@manzoorwanijk

@manzoorwanijk manzoorwanijk commented Sep 10, 2026 •

Copy link
Copy Markdown
Member

What?

Closes #82328
Closes #74877
Supersedes #82689

Moves the repository to npm v12 and records the supply chain policy the new major requires.

Why?

npm v12 is a security release: dependency install scripts, git dependencies and remote URL dependencies all become opt-in. The Node.js Release WG will not bundle it on Node.js 22, 24 or 26, so waiting costs another year with the protections off.

How?

devEngines.packageManager.version is the single source of truth since #82235, so CI and the release tooling pick up >=12.0.2 from the one-line bump.

allowScripts denies every dependency that ships an install script, so nothing compiles on install. .npmrc adds strict-allow-scripts, so an unlisted script fails the install rather than being skipped silently, and refuses local tarballs.

@wordpress/icons is the one approval. npm 12 does not exempt workspace lifecycle scripts from allowScripts under install-strategy=linked (npm/cli#9982), so without it src/library never generates on install.

Testing Instructions

  1. npm install --global npm@12.
  2. Remove every node_modules, then npm ci. The lockfile should be unchanged and packages/icons/src/library populated.
  3. Confirm each gate fires (the third edits package.json):
npm install --dry-run --no-save github:sindresorhus/is-odd
npm install --dry-run --no-save https://registry.npmjs.org/is-odd/-/is-odd-3.0.1.tgz
npm pkg delete allowScripts.esbuild && npm install --dry-run
git checkout package.json

Testing Instructions for Keyboard

N/A, no user interface change.

Use of AI Tools

Claude Code drafted and verified the changes against clean installs. I reviewed them.

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

🤖 PR meta 🤖

🏷️ Labels

This pull request needs exactly one label indicating its type, and has 0.

  • Required: any label starting with [Type].
  • Found: none.

Read more about Type labels in Gutenberg. If you cannot add labels yourself, a reviewer can do it for you.

📦 Bundle size

Size Change: 0 B

Total Size: 8.25 MB

5fdb2d7 Run

⚡ Performance

Show the results

Client side metrics exclude the server response time.

front-end-block-theme

Metric f37e70d trunk % Change
timeToFirstByte 56.7 ms +10.67% -3% 55.9 ms +6.44% -2.77% 1.43%
largestContentfulPaint 96 ms +4.17% -6.25% 94 ms +4.26% -6.38% 2.13%
lcpMinusTtfb 34.4 ms +23.69% -3.78% 34.55 ms +21.13% -2.6% -0.43%
wpBeforeTemplate 28.02 ms +19.66% -1.71% 27.64 ms +8.76% -1.12% 1.37%
wpTemplate 24.3 ms +3.87% -2.14% 23.64 ms +5.8% -1.31% 2.79%
wpTotal 53.13 ms +10.37% -3.07% 52.25 ms +6.68% -2.7% 1.68%
wpMemoryUsage 7.63 MB +0% -0% 7.59 MB +0% -0% 0.46%
wpDbQueries 17 +0% -0% 17 +0% -0% 0%

front-end-classic-theme

Metric f37e70d trunk % Change
timeToFirstByte 47.35 ms +4.33% -1.9% 47.9 ms +4.8% -2.82% -1.15%
largestContentfulPaint 100 ms +4% -0% 102 ms +1.96% -1.96% -1.96%
lcpMinusTtfb 54.2 ms +3.23% -1.85% 53.3 ms +4.32% -2.81% 1.69%
wpBeforeTemplate 26.28 ms +6.7% -2.17% 26.32 ms +7.45% -1.44% -0.15%
wpTemplate 17.67 ms +4.92% -0.74% 17.76 ms +5.07% -1.63% -0.51%
wpTotal 44.38 ms +4.35% -2.05% 44.99 ms +4.18% -3.22% -1.36%
wpMemoryUsage 6.25 MB +0% -0% 6.21 MB +0% -0% 0.71%
wpDbQueries 14 +0% -0% 14 +0% -0% 0%

media-processing

Metric f37e70d trunk % Change
mediaProcessingJpeg 399.76 ms +1.19% -0.6% 400.69 ms +1.01% -0.68% -0.23%
mediaProcessingAvif 6028.7 ms +0.17% -0.13% 6019.86 ms +0.37% -0.06% 0.15%
mediaProcessingJpegToAvif 4153.35 ms +0.4% -0.26% 4157.94 ms +0.26% -0.14% -0.11%

media-upload

Metric f37e70d trunk % Change
jpegUploadProcessing 1424.4 ms +36.64% -1.52% 1425.03 ms +0.35% -0.95% -0.04%
pngUploadProcessing 185.8 ms +10.89% -6.71% 205.06 ms +4.44% -10.63% -9.39%
largeJpegUploadProcessing 1417.88 ms +0.3% -0.62% 1407.25 ms +0.84% -1.02% 0.76%
multipleImageUploadProcessing 1560.99 ms +9.22% -1.12% 1578.57 ms +0.98% -1.15% -1.11%

post-editor

Metric f37e70d trunk % Change
serverResponse 494.92 ms +11.13% -3.52% 521.2 ms +5.12% -5.29% -5.04%
firstPaint 316.87 ms +30.28% -23.1% 240.8 ms +36.07% -15.29% 31.59%
domContentLoaded 1131.37 ms +0.41% -2.21% 1116.77 ms +2.15% -2.67% 1.31%
loaded 1132.78 ms +0.42% -2.2% 1117.98 ms +2.15% -2.63% 1.32%
firstContentfulPaint 463.28 ms +4.49% -1.74% 456.06 ms +3.16% -2.25% 1.58%
firstBlock 3383.46 ms +1.49% -0.53% 3380.8 ms +0.98% -2.17% 0.08%
type 18.31 ms +6.44% -6.77% 19.03 ms +3.05% -5.31% -3.78%
typeWithoutInspector 18 ms +6.78% -2.67% 17.69 ms +8.93% -5.09% 1.75%
typeWithTopToolbar 22.86 ms +8.75% -3.67% 23.37 ms +4.71% -3.64% -2.18%
typeContainer 8.95 ms +5.47% -8.16% 8.54 ms +8.08% -5.85% 4.8%
focus 77.44 ms +18.44% -8.16% 69.86 ms +12.94% -5.85% 10.85%
firstFocus 205.55 ms +0% -0% 204.06 ms +0% -0% 0.73%
selectAll 524.67 ms +5.3% -0.15% 564.74 ms +1.06% -5.86% -7.1%
listViewOpen 63.19 ms +6.58% -0.22% 67.25 ms +6.36% -8.04% -6.04%
inserterOpen 24.8 ms +7.26% -14.56% 23.37 ms +8.47% -8.13% 6.12%
inserterHover 2.17 ms +7.37% -7.37% 2.27 ms +25.11% -13.22% -4.41%
inserterSearch 8.52 ms +7.04% -6.57% 7.97 ms +2.38% -9.16% 6.9%
loadPatterns 669.72 ms +1.16% -3.54% 662.85 ms +3.46% -3.34% 1.04%
wpTotal 485.01 ms +11.24% -3.52% 511.07 ms +5% -5.43% -5.1%
wpMemoryUsage 13.18 MB +0% -0% 13.14 MB +0% -0% 0.28%
wpDbQueries 54 +0% -0% 54 +0% -1.85% 0%

site-editor

Metric f37e70d trunk % Change
serverResponse 443.61 ms +4.39% -4.56% 434.99 ms +2.64% -3.63% 1.98%
firstPaint 268.57 ms +18.9% -13.19% 251.32 ms +15.86% -17.45% 6.86%
domContentLoaded 1256.02 ms +4.68% -5.81% 1145.17 ms +3.78% -5.21% 9.68%
loaded 1257.56 ms +4.68% -5.8% 1146.4 ms +3.81% -5.19% 9.7%
firstContentfulPaint 523.25 ms +3.88% -10.63% 474.17 ms +4.48% -7.23% 10.35%
firstBlock 4480.84 ms +3.85% -4.19% 3946.89 ms +5.67% -1.76% 13.53%
type 19.89 ms +5.58% -4.32% 21.62 ms +6.89% -5.18% -8%
navigate 146.65 ms +10.07% -8.78% 136.05 ms +7.3% -17.07% 7.79%
loadPatterns 1535.34 ms +5.77% -14.38% 1548.87 ms +16.19% -8.59% -0.87%
loadPages 1054.3 ms +9.33% -2.02% 1061.18 ms +2.75% -2.34% -0.65%
wpTotal 433.28 ms +4.27% -4.97% 424.85 ms +2.52% -3.9% 1.98%
wpMemoryUsage 12.14 MB +0% -0% 12.10 MB +0% -0% 0.3%
wpDbQueries 43 +2.33% -0% 43 +2.33% -0% 0%

5fdb2d7 Run

Comment thread package.json
"core-js": false,
"core-js-pure": false,
"esbuild": false,
"file:packages/icons": true,

@manzoorwanijk manzoorwanijk Oct 2, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file:packages/icons here is a temporary workaround for a bug in npm CLI, which is being fixed in npm/cli#9990

Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts, all
denied: nothing compiles on install.

npm 12 does not exempt workspace lifecycle scripts from allowScripts
under install-strategy=linked, so @wordpress/icons needs an entry of its
own to keep generating src/library on install. See
npm/cli#9982.

Closes #82328. Supersedes #82689.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Framework: Update npm to v12 Implement ignore-scripts to harden npm usage

1 participant