Skip to content

build(deps-dev): bump np from 10.2.0 to 11.0.0#409

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/np-11.0.0
Closed

build(deps-dev): bump np from 10.2.0 to 11.0.0#409
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/np-11.0.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 22, 2026

Bumps np from 10.2.0 to 11.0.0.

Release notes

Sourced from np's releases.

v11.0.0

Breaking

  • Require Node.js 20 307ebec

Improvements

  • Support passkey authentication via automatic browser opening 1ef9af7
  • Support publishing via OIDC authentication (#772) 3ded31e
  • Add --no-release-notes flag 4f910a2
  • Add --remote flag to specify Git remote 4d5fb6a
  • Add prerequisite check for package entry points 7dcd833
  • Require major version bump when dropping Node.js support 3ed286a
  • Add interactive prerelease identifier selection 6b51dda
  • Support GPG password prompts during version bumping 5a96f80
  • Show unpublished files as warning instead of blocking prompt efcc05e
  • Add npm provenance support d8f3322
  • Add git user configuration check to prevent npm version failures ebb9acf

Fixes

  • Fix --contents flag not being respected when publishing 53904d0
  • Fix compatibility with some external registries c6ef15d
  • Fix repository URL parsing for shorthand and GitHub Enterprise URLs 02b4ed9
  • Fix Yarn Berry detection when packageManager field is missing 7009b77
  • Fix ENOWORKSPACES error when publishing from monorepo workspace 0a8af7b
  • Fix rejection of explicit version numbers ebdcbaa
  • Fix publish hanging indefinitely a651fc4
  • Fix first publish failure for prerelease versions with npm 10+ 3811182
  • Fix subfolder publishing broken since npm 8.5 e996c6f
  • Fix CLI default flags overriding local config values 3804d0b
  • Fix publishConfig handling for access and registry fields 753abb4
  • Fix npm pack JSON parsing when lifecycle scripts output to stdout a13bba2
  • Fix git commands failing with password-protected SSH keys 67b6aff
  • Fix failure with repositories that have multiple initial commits 869f80b
  • Fix package.json config being ignored with global installation 08a3f64
  • Fix long release notes exceeding GitHub URL limit a160aff
  • Fix some network calls never timing out 6a11153
  • Fix contents config option being ignored 88226d7
  • Fix contents option being interpreted as package name 521ecfc
  • Fix incorrect commit range when tags are created out of order fea3eb7
  • Fix getNpmPackageAccess to respect publishConfig.registry 15040c8
  • Fix authentication when publishConfig.registry is official npm registry 380fd24

sindresorhus/np@v10.3.0...v11.0.0

v10.3.0

  • Auto-run npm login on authentication failure 38abeee

... (truncated)

Commits
  • 45404ba 11.0.0
  • 16628c7 Minor tweaks
  • 53904d0 Fix --contents flag not being respected when publishing
  • 4d5fb6a Add --remote flag to specify Git remote
  • 7dcd833 Add prerequisite check for package entry points
  • 3ed286a Require major version bump when dropping Node.js support
  • c6ef15d Fix compatibility with some external registries
  • 02b4ed9 Fix repository URL parsing for shorthand and GitHub Enterprise URLs
  • 1ef9af7 Support passkey authentication via automatic browser opening
  • 7009b77 Fix Yarn Berry detection when packageManager field is missing
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [np](https://github.com/sindresorhus/np) from 10.2.0 to 11.0.0.
- [Release notes](https://github.com/sindresorhus/np/releases)
- [Commits](sindresorhus/np@v10.2.0...v11.0.0)

---
updated-dependencies:
- dependency-name: np
  dependency-version: 11.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jan 22, 2026
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 23, 2026

Superseded by #410.

@dependabot dependabot bot closed this Jan 23, 2026
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/np-11.0.0 branch January 23, 2026 04:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants