Skip to content

Tags: npm/pacote

Tags

v21.5.1

Toggle v21.5.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.5.1 (#499)

🤖 I have created a release *beep* *boop*
---


## [21.5.1](v21.5.0...v21.5.1)
(2026-06-09)
### Bug Fixes
*
[`627a7dc`](627a7dc)
[#499](#499) avoid ReDoS in addGitSha
committish stripping (@owlstronaut)
### Chores
*
[`790a24b`](790a24b)
[#500](#500) template-oss-apply (#500)
(@owlstronaut, test)
*
[`09cb304`](09cb304)
[#499](#499) template-oss-apply
(@owlstronaut)
*
[`bea9f84`](bea9f84)
[#499](#499)
`@npmcli/template-oss@5.1.0` (@owlstronaut)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.5.0

Toggle v21.5.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.5.0 (#470)

🤖 I have created a release *beep* *boop*
---


## [21.5.0](v21.4.0...v21.5.0)
(2026-03-09)
### Features
*
[`d912f17`](d912f17)
[#457](#457) expose fetched
attestation bundles on manifest (#457) (@mitchdenny)
### Chores
*
[`586a55d`](586a55d)
[#471](#471) template-oss-apply for
new macos images (#471) (@wraithgar)
*
[`d1cc5c8`](d1cc5c8)
[#460](#460) template-oss-apply for
release branches (#460) (@wraithgar)
*
[`b741e8b`](b741e8b)
[#468](#468) bump @npmcli/template-oss
from 4.28.0 to 4.29.0 (#468) (@dependabot[bot], @npm-cli-bot)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v20.0.1

Toggle v20.0.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 20.0.1 (#464)

🤖 I have created a release *beep* *boop*
---


## [20.0.1](v20.0.0...v20.0.1)
(2026-03-06)
### Dependencies
*
[`f8e2931`](f8e2931)
[#461](#461) `tar@7.5.10`
### Chores
*
[`01a126d`](01a126d)
[#466](#466) enable backport mode for
v20 (#466) (@wraithgar)
*
[`98f72f6`](98f72f6)
[#461](#461) tests should not inherit
--ignore-scripts flag from `npm run t… (#422) (@owlstronaut)
*
[`f8cf9ba`](f8cf9ba)
[#461](#461)
`@npmcli/template-oss@4.29.0` (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v19.0.2

Toggle v19.0.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 19.0.2 (#463)

🤖 I have created a release *beep* *boop*
---


## [19.0.2](v19.0.1...v19.0.2)
(2026-03-06)
### Dependencies
*
[`bf6e354`](bf6e354)
[#459](#459) `tar@7.5.10`
### Chores
*
[`b7f2691`](b7f2691)
[#465](#465) enable backport mode for
v19 (#465) (@wraithgar)
*
[`ed1aef0`](ed1aef0)
[#459](#459) tests should not inherit
--ignore-scripts flag from `npm run t… (#422) (@owlstronaut)
*
[`415e369`](415e369)
[#459](#459)
`@npmcli/template-oss@4.29.0` (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.4.0

Toggle v21.4.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.4.0 (#455)

🤖 I have created a release *beep* *boop*
---


## [21.4.0](v21.3.1...v21.4.0)
(2026-02-24)
### Features
*
[`6912f24`](6912f24)
[#451](#451) add allowRegistry option
(#451) (@wraithgar)
### Bug Fixes
*
[`ab37bc1`](ab37bc1)
[#452](#452) prevent path duplication
in attestation URL for registries with … (#452) (@ajayk)
*
[`ab37bc1`](ab37bc1)
[#452](#452) prevent path duplication
in attestation URL for registries with (@ajayk)
*
[`8b8ea3b`](8b8ea3b)
[#454](#454) skip registry key check
for keyless (Sigstore/Fulcio) attestations (#454) (@ajayk)
*
[`8b8ea3b`](8b8ea3b)
[#454](#454) skip registry key check
for keyless (Sigstore/Fulcio) attestations (@ajayk)
### Chores
*
[`0dfd1cd`](0dfd1cd)
[#456](#456) remove git config from
tests (#456) (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.3.1

Toggle v21.3.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.3.1 (#448)

🤖 I have created a release *beep* *boop*
---


## [21.3.1](v21.3.0...v21.3.1)
(2026-02-10)
### Bug Fixes
*
[`96e571a`](96e571a)
[#439](#439) ensure that resolved git
ref matches expected sha (#439) (@klassiker, pacotedev)
### Chores
*
[`91847c4`](91847c4)
[#447](#447) fix test for ssri
ignoring invalid hashes (#447) (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.3.0

Toggle v21.3.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.3.0 (#446)

🤖 I have created a release *beep* *boop*
---


## [21.3.0](v21.2.0...v21.3.0)
(2026-02-09)
### Features
*
[`8f5091d`](8f5091d)
[#445](#445) add support for git-256
sha lengths (#445) (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.2.0

Toggle v21.2.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.2.0 (#444)

🤖 I have created a release *beep* *boop*
---


## [21.2.0](v21.1.0...v21.2.0)
(2026-02-06)
### Features
*
[`db21624`](db21624)
[#442](#442) implement gitSubdir
according to npa spec (#442) (@Kakadus)
*
[`c2a4217`](c2a4217)
[#443](#443) add allowRemote,
allowFile, allowDirectory (#443) (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.1.0

Toggle v21.1.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.1.0 (#441)

🤖 I have created a release *beep* *boop*
---


## [21.1.0](v21.0.4...v21.1.0)
(2026-01-28)
### Features
*
[`258e5fd`](258e5fd)
[#440](#440) add allowGit option
(#440) (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

v21.0.4

Toggle v21.0.4's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore: release 21.0.4 (#437)

🤖 I have created a release *beep* *boop*
---


## [21.0.4](v21.0.3...v21.0.4)
(2025-11-13)
### Dependencies
*
[`edbcc02`](edbcc02)
[#436](#436) `proc-log@6.0.0`
*
[`8dc1f22`](8dc1f22)
[#436](#436)
`@npmcli/installed-package-contents@4.0.0`
*
[`505c3b0`](505c3b0)
[#436](#436) `ssri@13.0.0`
*
[`a23fb17`](a23fb17)
[#436](#436)
`@npmcli/promise-spawn@9.0.0`
### Chores
*
[`ff261aa`](ff261aa)
[#436](#436)
`@npmcli/eslint-config@6.0.0` (@wraithgar)
*
[`2bba862`](2bba862)
[#436](#436)
`@npmcli/template-oss@4.28.0` (@wraithgar)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>