Summary
npm 12 (12.0.0, released 2026-07-08) changed npm info <pkg> --json to wrap its output in an array, even for a single package spec:
$ npx -y npm@11 info react --json | jq 'type'
"object"
$ npx -y npm@12 info react --json | jq 'type'
"array"
getPackageInfo() in packages/cli/src/commands/publish/npm-utils.ts returns jsonParse(result.stdout.toString()) unmodified, and its callers read properties off the result (pkgInfo.error, pkgInfo.versions). With npm 12 those are properties of the wrapping array, so they are always undefined. As a consequence, in getUnpublishedPackages():
- publishedVersions = response.pkgInfo.versions || [] is always [], so every package is treated as unpublished — the log shows X is being published because our local version (…) has not been published on npm for packages whose current version is already on the registry, and changeset publish attempts to republish all of them;
- only-pre detection (response.pkgInfo.versions && versions.every(...)) never triggers;
- E404 detection in infoAllow404() (pkgInfo.error?.code === "E404") also can't work.
On 2.31.0 the duplicate publish attempts then crash the whole run with TypeError: Cannot read properties of undefined (reading 'includes') at isAlreadyPublishedError (that secondary crash was fixed by #2132, thanks!) — but even with that fix, detection is still wrong and every release run re-attempts publishes of already-published versions instead of skipping them up front.
This starts happening for anyone whose CI installs npm@latest (a common pattern, e.g. for npm trusted publishing), which now resolves to 12.x.
Reproduction
In any monorepo where at least one package's current version is already published:
- run: npm install -g npm@latest # >= 12.0.0
- run: npx changeset publish
Observed: <pkg> is being published because our local version (x.y.z) has not been published on npm for already-published packages, followed by failed duplicate publishes. Expected: <pkg> is not being published because version x.y.z is already published on npm.
Root cause
npm 12's npm view/npm info --json output format change (results are now always emitted as an array). The data itself is unchanged — the packument object with the full versions array is the array's single element — it's just wrapped.
Suggested fix
Unwrap in getPackageInfo() (or jsonParse), e.g.:
const parsed = jsonParse(result.stdout.toString());
return Array.isArray(parsed) ? parsed[0] ?? { error: { code: "E404" } } : parsed;
Happy to open a PR if that direction sounds right.
Environment
- @changesets/cli 2.31.0 (the parsing in getPackageInfo is unchanged on current main)
- npm 12.0.1 / Node 22 (GitHub Actions ubuntu-latest)
- publish tool: pnpm 11.10.0
Workaround
Pin npm 11 in CI: npm install -g npm@11.
Summary
npm 12 (12.0.0, released 2026-07-08) changed npm info <pkg> --json to wrap its output in an array, even for a single package spec:
getPackageInfo() in packages/cli/src/commands/publish/npm-utils.ts returns jsonParse(result.stdout.toString()) unmodified, and its callers read properties off the result (pkgInfo.error, pkgInfo.versions). With npm 12 those are properties of the wrapping array, so they are always undefined. As a consequence, in getUnpublishedPackages():
On 2.31.0 the duplicate publish attempts then crash the whole run with TypeError: Cannot read properties of undefined (reading 'includes') at isAlreadyPublishedError (that secondary crash was fixed by #2132, thanks!) — but even with that fix, detection is still wrong and every release run re-attempts publishes of already-published versions instead of skipping them up front.
This starts happening for anyone whose CI installs npm@latest (a common pattern, e.g. for npm trusted publishing), which now resolves to 12.x.
Reproduction
In any monorepo where at least one package's current version is already published:
Observed: <pkg> is being published because our local version (x.y.z) has not been published on npm for already-published packages, followed by failed duplicate publishes. Expected: <pkg> is not being published because version x.y.z is already published on npm.
Root cause
npm 12's npm view/npm info --json output format change (results are now always emitted as an array). The data itself is unchanged — the packument object with the full versions array is the array's single element — it's just wrapped.
Suggested fix
Unwrap in getPackageInfo() (or jsonParse), e.g.:
Happy to open a PR if that direction sounds right.
Environment
Workaround
Pin npm 11 in CI: npm install -g npm@11.