RTC NPM Resource Changed PR-5.4-dev Pending

User tests: Successful: Unsuccessful:

avatar brianteeman
brianteeman
10 Jul 2026

Pull Request resolves # .

  • I read the Generative AI policy and my contribution is either not created with the help of AI or is compatible with the policy and GNU/GPL 2 or later.

Summary of Changes

With npm 12 you now need to explicitly allow scripts see https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/

Testing Instructions

if you are on npm 11.6 and higher and run npm i you will see information at the end that you need to allow certain scripts.

Actual result BEFORE applying this Pull Request

npm warn install-scripts 5 packages had install scripts blocked because they are not covered by allowScripts:
npm warn install-scripts   core-js@3.45.1 (postinstall: node -e "try{require('./postinstall')}catch(e){}")
npm warn install-scripts   cypress@15.18.0 (postinstall: node dist/index.js --exec install)
npm warn install-scripts   esbuild@0.25.10 (postinstall: node install.js)
npm warn install-scripts   cypress@13.17.0 (postinstall: node index.js --exec install)
npm warn install-scripts   vue-demi@0.13.11 (postinstall: node ./scripts/postinstall.js)
npm warn install-scripts
npm warn install-scripts Run `npm install-scripts ls` to review, or `npm install-scripts approve <pkg>` to allow.

Expected result AFTER applying this Pull Request

no warnings

Link to documentations

Please select:

  • Documentation link for guide.joomla.org:

  • No documentation changes for guide.joomla.org needed

  • Pull Request link for manual.joomla.org:

  • No documentation changes for manual.joomla.org needed

avatar brianteeman brianteeman - open - 10 Jul 2026
avatar brianteeman brianteeman - change - 10 Jul 2026
Status New ⇒ Pending
avatar joomla-cms-bot joomla-cms-bot - change - 10 Jul 2026
Category ⇒ NPM Change
avatar brianteeman brianteeman - change - 11 Jul 2026
The description was changed
avatar brianteeman brianteeman - edited - 11 Jul 2026
avatar CSGoat0 CSGoat0 - test_item - 14 Jul 2026 - Tested successfully
avatar CSGoat0
CSGoat0 - comment - 14 Jul 2026

I have tested this item ✅ successfully on 7e2ee6d


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.

avatar CSGoat0
CSGoat0 - comment - 14 Jul 2026

I have tested this item ✅ successfully on 7e2ee6d


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.

avatar ThomasFinnern ThomasFinnern - test_item - 14 Jul 2026 - Tested successfully
avatar ThomasFinnern
ThomasFinnern - comment - 14 Jul 2026

I have tested this item ✅ successfully on 7e2ee6d

Tested on npm 11.18.0.
The last lines had the warning lines before the patch was applied. Then gone


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.

avatar ThomasFinnern
ThomasFinnern - comment - 14 Jul 2026

I have tested this item ✅ successfully on 7e2ee6d

Tested on npm 11.18.0.
The last lines had the warning lines before the patch was applied. Then gone


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.

avatar richard67
richard67 - comment - 14 Jul 2026

Do the new allow script directives work also with older npm versions where they might not be used? Or do they cause errors or warnings on these older versions? Has anyone checked that?

avatar CSGoat0
CSGoat0 - comment - 14 Jul 2026

Do the new allow script directives work also with older npm versions where they might not be used? Or do they cause errors or warnings on these older versions? Has anyone checked that?

Didn't check it with older versions, I had an old version of npm that doesn't show warnings on npm i so needed to update first to see the warnings before applying the PR. Didn't think of that scenario.

avatar brianteeman
brianteeman - comment - 14 Jul 2026

I downgraded to npm 10.1 and then ran npm i with this PR. No errors or warnings on completion which is what I would expect as that version will happily process the scripts

avatar richard67 richard67 - change - 14 Jul 2026
The description was changed
Status Pending ⇒ Ready to Commit
Labels Added: NPM Resource Changed PR-5.4-dev
avatar richard67
richard67 - comment - 14 Jul 2026

RTC


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.

avatar richard67 richard67 - edited - 14 Jul 2026
avatar richard67
richard67 - comment - 14 Jul 2026

RTC


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.

avatar brianteeman brianteeman - change - 17 Jul 2026
Labels Added: RTC
avatar brianteeman
brianteeman - comment - 17 Jul 2026

can we have some more tests on macOS please as there has been a macOS specific change

avatar muhme
muhme - comment - 17 Jul 2026

can we have some more tests on macOS please as there has been a macOS specific change

Thanks for pointing that out, but updating allowScripts will remain an ongoing task in the future anyway. I’ll therefore proceed with the final tests and the merge.

avatar brianteeman
brianteeman - comment - 17 Jul 2026

we need to be aware in the future that this can be OS specific

avatar muhme
muhme - comment - 17 Jul 2026

✅ Final test before merge with macOS command line

  • With npm 11.17.0 seen the allow-scripts warnings and one more for fsevents@2.3.3 as I am on macOS
  • Created the change by own with npm approve-scripts --all and and moved the package.json file aside
    • Changes in the PRs are identical with the changes I made myself
  • Applied PR with gh pr checkout 48073
    • With npm 11.17.0, there are no longer any allow-scripts warnings
    • Tested with npm 11.12.1 npm ci is still working
avatar muhme muhme - change - 17 Jul 2026
Status Ready to Commit ⇒ Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 ⇒ 2026-07-17 10:21:06
Closed_By ⇒ muhme
avatar muhme muhme - close - 17 Jul 2026
avatar muhme muhme - merge - 17 Jul 2026
avatar muhme
muhme - comment - 17 Jul 2026

Dear release manager or maintainer: npm v12 introduces security-related changes to the default behaviour of npm install. This requires the new allowScripts section in the package.json file introduced with this PR.

⚠️ As the packages are version-pinned, the entries need to be reviewed whenever dependencies change.
⚠️ Please also be aware that there are OS-specific packages, such as fsevents for macOS.

Starting with npm v11.16, warnings are shown, while in npm v12 the installation scripts are no longer executed if a version-pinned package is missing from allowScripts.

Add a Comment

Login with GitHub to post a comment