FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

`npm info --json` array output in npm 12 breaks published-version detection in `changeset publish` · Issue #2164 · changesets/changesets · GitHub

Repository navigation

npm info --json array output in npm 12 breaks published-version detection in changeset publish #2164

Description

Summary

npm 12 (12.0.0, released 2026-07-08) changed npm info <pkg> --json to wrap its output in an array, even for a single package spec:

$ npx -y npm@11 info react --json | jq 'type'
"object"

$ npx -y npm@12 info react --json | jq 'type'
"array"

getPackageInfo() in packages/cli/src/commands/publish/npm-utils.ts returns jsonParse(result.stdout.toString()) unmodified, and its callers read properties off the result (pkgInfo.error, pkgInfo.versions). With npm 12 those are properties of the wrapping array, so they are always undefined. As a consequence, in getUnpublishedPackages():

  • publishedVersions = response.pkgInfo.versions || [] is always [], so every package is treated as unpublished — the log shows X is being published because our local version (…) has not been published on npm for packages whose current version is already on the registry, and changeset publish attempts to republish all of them;
  • only-pre detection (response.pkgInfo.versions && versions.every(...)) never triggers;
  • E404 detection in infoAllow404() (pkgInfo.error?.code === "E404") also can't work.

On 2.31.0 the duplicate publish attempts then crash the whole run with TypeError: Cannot read properties of undefined (reading 'includes') at isAlreadyPublishedError (that secondary crash was fixed by #2132, thanks!) — but even with that fix, detection is still wrong and every release run re-attempts publishes of already-published versions instead of skipping them up front.

This starts happening for anyone whose CI installs npm@latest (a common pattern, e.g. for npm trusted publishing), which now resolves to 12.x.

Reproduction

In any monorepo where at least one package's current version is already published:

- run: npm install -g npm@latest   # >= 12.0.0
- run: npx changeset publish

Observed: <pkg> is being published because our local version (x.y.z) has not been published on npm for already-published packages, followed by failed duplicate publishes. Expected: <pkg> is not being published because version x.y.z is already published on npm.

Root cause

npm 12's npm view/npm info --json output format change (results are now always emitted as an array). The data itself is unchanged — the packument object with the full versions array is the array's single element — it's just wrapped.

Suggested fix

Unwrap in getPackageInfo() (or jsonParse), e.g.:

const parsed = jsonParse(result.stdout.toString());
return Array.isArray(parsed) ? parsed[0] ?? { error: { code: "E404" } } : parsed;

Happy to open a PR if that direction sounds right.

Environment

  • @changesets/cli 2.31.0 (the parsing in getPackageInfo is unchanged on current main)
  • npm 12.0.1 / Node 22 (GitHub Actions ubuntu-latest)
  • publish tool: pnpm 11.10.0

Workaround

Pin npm 11 in CI: npm install -g npm@11.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL