Skip to content

chore(deps): bump tar, @npmcli/run-script, cacache, make-fetch-happen, node-gyp, npm-profile, npm-registry-fetch and pacote#20

Open
dependabot[bot] wants to merge 1 commit intolatestfrom
dependabot/npm_and_yarn/multi-dee73cdbae
Open

chore(deps): bump tar, @npmcli/run-script, cacache, make-fetch-happen, node-gyp, npm-profile, npm-registry-fetch and pacote#20
dependabot[bot] wants to merge 1 commit intolatestfrom
dependabot/npm_and_yarn/multi-dee73cdbae

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jan 29, 2026

Bumps tar, @npmcli/run-script, cacache, make-fetch-happen, node-gyp, npm-profile, npm-registry-fetch and pacote. These dependencies needed to be updated together.
Updates tar from 6.1.11 to 7.5.7

Release notes

Sourced from tar's releases.

v6.1.13

6.1.13 (2022-12-07)

Dependencies

v6.1.12

6.1.12 (2022-10-31)

Bug Fixes

Documentation

Changelog

Sourced from tar's changelog.

Changelog

7.5

  • Added zstd compression support.
  • Consistent TOCTOU behavior in sync t.list
  • Only read from ustar block if not specified in Pax
  • Fix sync tar.list when file size reduces while reading
  • Sanitize absolute linkpaths properly
  • Prevent writing hardlink entries to the archive ahead of their file target

7.4

  • Deprecate onentry in favor of onReadEntry for clarity.

7.3

  • Add onWriteEntry option

7.2

  • DRY the command definitions into a single makeCommand method, and update the type signatures to more appropriately infer the return type from the options and arguments provided.

7.1

  • Update minipass to v7.1.0
  • Update the type definitions of write() and end() methods on Unpack and Parser classes to be compatible with the NodeJS.WritableStream type in the latest versions of @types/node.

7.0

  • Drop support for node <18
  • Rewrite in TypeScript, provide ESM and CommonJS hybrid interface
  • Add tree-shake friendly exports, like import('tar/create') and import('tar/read-entry') to get individual functions or classes.
  • Add chmod option that defaults to false, and deprecate noChmod. That is, reverse the default option regarding explicitly setting file system modes to match tar entry settings.
  • Add processUmask option to avoid having to call process.umask() when chmod: true (or noChmod: false) is set.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by isaacs, a new releaser for tar since your current version.


Updates @npmcli/run-script from 4.2.0 to 10.0.3

Release notes

Sourced from @​npmcli/run-script's releases.

v10.0.3

10.0.3 (2025-11-13)

Dependencies

Chores

v10.0.2

10.0.2 (2025-10-24)

Dependencies

Chores

v10.0.1

10.0.1 (2025-10-23)

Dependencies

Chores

v10.0.0

10.0.0 (2025-09-02)

⚠️ BREAKING CHANGES

  • run-script now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Dependencies

Chores

v9.1.0

9.1.0 (2025-03-07)

Features

Chores

v9.0.2

9.0.2 (2024-12-04)

Dependencies

Chores

v9.0.1

... (truncated)

Changelog

Sourced from @​npmcli/run-script's changelog.

10.0.3 (2025-11-13)

Dependencies

Chores

10.0.2 (2025-10-24)

Dependencies

Chores

10.0.1 (2025-10-23)

Dependencies

Chores

10.0.0 (2025-09-02)

⚠️ BREAKING CHANGES

  • run-script now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Dependencies

Chores

9.1.0 (2025-03-07)

Features

Chores

9.0.2 (2024-12-04)

Dependencies

Chores

9.0.1 (2024-10-02)

Dependencies

9.0.0 (2024-09-26)

⚠️ BREAKING CHANGES

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​npmcli/run-script since your current version.


Updates cacache from 16.1.1 to 20.0.3

Release notes

Sourced from cacache's releases.

v20.0.3

20.0.3 (2025-11-19)

Dependencies

Chores

v20.0.2

20.0.2 (2025-11-17)

Dependencies

v20.0.1

20.0.1 (2025-08-18)

Dependencies

v20.0.0

20.0.0 (2025-07-24)

⚠️ BREAKING CHANGES

  • cacache now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Dependencies

Chores

v19.0.1

19.0.1 (2024-09-26)

Dependencies

v19.0.0

19.0.0 (2024-09-26)

⚠️ BREAKING CHANGES

  • cacache now supports node ^18.17.0 || >=20.5.0

Bug Fixes

Dependencies

... (truncated)

Changelog

Sourced from cacache's changelog.

20.0.3 (2025-11-19)

Dependencies

Chores

20.0.2 (2025-11-17)

Dependencies

20.0.1 (2025-08-18)

Dependencies

20.0.0 (2025-07-24)

⚠️ BREAKING CHANGES

  • cacache now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Dependencies

Chores

19.0.1 (2024-09-26)

Dependencies

19.0.0 (2024-09-26)

⚠️ BREAKING CHANGES

  • cacache now supports node ^18.17.0 || >=20.5.0

Bug Fixes

Dependencies

Chores

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for cacache since your current version.


Updates make-fetch-happen from 10.2.0 to 15.0.3

Release notes

Sourced from make-fetch-happen's releases.

v15.0.3

15.0.3 (2025-11-13)

Dependencies

v15.0.2

15.0.2 (2025-09-18)

Dependencies

v15.0.1

15.0.1 (2025-08-19)

Dependencies

v15.0.0

15.0.0 (2025-07-24)

⚠️ BREAKING CHANGES

  • make-fetch-happen now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Dependencies

Chores

v14.0.3

14.0.3 (2024-10-21)

Bug Fixes

Dependencies

v14.0.2

14.0.2 (2024-10-16)

Bug Fixes

Chores

v14.0.1

14.0.1 (2024-10-02)

Dependencies

v14.0.0

... (truncated)

Changelog

Sourced from make-fetch-happen's changelog.

15.0.3 (2025-11-13)

Dependencies

15.0.2 (2025-09-18)

Dependencies

15.0.1 (2025-08-19)

Dependencies

15.0.0 (2025-07-24)

⚠️ BREAKING CHANGES

  • make-fetch-happen now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Dependencies

Chores

14.0.3 (2024-10-21)

Bug Fixes

Dependencies

14.0.2 (2024-10-16)

Bug Fixes

Chores

14.0.1 (2024-10-02)

Dependencies

14.0.0 (2024-09-26)

⚠️ BREAKING CHANGES

  • make-fetch-happen now supports node ^18.17.0 || >=20.5.0

Bug Fixes

Dependencies

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for make-fetch-happen since your current version.


Updates node-gyp from 9.0.0 to 12.2.0

Release notes

Sourced from node-gyp's releases.

v12.2.0

12.2.0 (2026-01-26)

Features

Bug Fixes

Core

Doc

Miscellaneous

v12.1.0

12.1.0 (2025-11-12)

Features

  • Add support for Visual Studio 2026 (18.x) (69e5fd2)
  • Support for Visual Studio 2026 (18.x) (69e5fd2)

v12.0.0

12.0.0 (2025-11-10)

⚠ BREAKING CHANGES

... (truncated)

Changelog

Sourced from node-gyp's changelog.

12.2.0 (2026-01-26)Description has been truncated

…, node-gyp, npm-profile, npm-registry-fetch and pacote

Bumps [tar](https://github.com/isaacs/node-tar), [@npmcli/run-script](https://github.com/npm/run-script), [cacache](https://github.com/npm/cacache), [make-fetch-happen](https://github.com/npm/make-fetch-happen), [node-gyp](https://github.com/nodejs/node-gyp), [npm-profile](https://github.com/npm/npm-profile), [npm-registry-fetch](https://github.com/npm/npm-registry-fetch) and [pacote](https://github.com/npm/pacote). These dependencies needed to be updated together.

Updates `tar` from 6.1.11 to 7.5.7
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v6.1.11...v7.5.7)

Updates `@npmcli/run-script` from 4.2.0 to 10.0.3
- [Release notes](https://github.com/npm/run-script/releases)
- [Changelog](https://github.com/npm/run-script/blob/main/CHANGELOG.md)
- [Commits](npm/run-script@v4.2.0...v10.0.3)

Updates `cacache` from 16.1.1 to 20.0.3
- [Release notes](https://github.com/npm/cacache/releases)
- [Changelog](https://github.com/npm/cacache/blob/main/CHANGELOG.md)
- [Commits](npm/cacache@v16.1.1...v20.0.3)

Updates `make-fetch-happen` from 10.2.0 to 15.0.3
- [Release notes](https://github.com/npm/make-fetch-happen/releases)
- [Changelog](https://github.com/npm/make-fetch-happen/blob/main/CHANGELOG.md)
- [Commits](npm/make-fetch-happen@v10.2.0...v15.0.3)

Updates `node-gyp` from 9.0.0 to 12.2.0
- [Release notes](https://github.com/nodejs/node-gyp/releases)
- [Changelog](https://github.com/nodejs/node-gyp/blob/main/CHANGELOG.md)
- [Commits](nodejs/node-gyp@v9.0.0...v12.2.0)

Updates `npm-profile` from 6.2.1 to 12.0.1
- [Release notes](https://github.com/npm/npm-profile/releases)
- [Changelog](https://github.com/npm/npm-profile/blob/main/CHANGELOG.md)
- [Commits](npm/npm-profile@v6.2.1...v12.0.1)

Updates `npm-registry-fetch` from 13.3.0 to 19.1.1
- [Release notes](https://github.com/npm/npm-registry-fetch/releases)
- [Changelog](https://github.com/npm/npm-registry-fetch/blob/main/CHANGELOG.md)
- [Commits](npm/npm-registry-fetch@v13.3.0...v19.1.1)

Updates `pacote` from 13.6.1 to 21.1.0
- [Release notes](https://github.com/npm/pacote/releases)
- [Changelog](https://github.com/npm/pacote/blob/main/CHANGELOG.md)
- [Commits](npm/pacote@v13.6.1...v21.1.0)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.7
  dependency-type: direct:production
- dependency-name: "@npmcli/run-script"
  dependency-version: 10.0.3
  dependency-type: direct:production
- dependency-name: cacache
  dependency-version: 20.0.3
  dependency-type: direct:production
- dependency-name: make-fetch-happen
  dependency-version: 15.0.3
  dependency-type: direct:production
- dependency-name: node-gyp
  dependency-version: 12.2.0
  dependency-type: direct:production
- dependency-name: npm-profile
  dependency-version: 12.0.1
  dependency-type: direct:production
- dependency-name: npm-registry-fetch
  dependency-version: 19.1.1
  dependency-type: direct:production
- dependency-name: pacote
  dependency-version: 21.1.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jan 29, 2026
@changeset-bot
Copy link

changeset-bot bot commented Jan 29, 2026

⚠️ No Changeset found

Latest commit: 34f4100

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants