Update verdaccio/verdaccio Docker tag to v6 - #13
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
October 16, 2024 20:49
c4d73aa to
0c4418e
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
November 17, 2024 16:43
0c4418e to
99383b2
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
3 times, most recently
from
December 21, 2024 11:08
fc1e1ff to
14ea053
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
April 20, 2025 23:43
14ea053 to
fb6f8cf
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
June 17, 2025 23:27
7fe2f5b to
a9632ea
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
June 29, 2025 13:39
a9632ea to
22565db
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
July 25, 2025 11:54
22565db to
fbc9519
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
September 30, 2025 01:54
fbc9519 to
c565085
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
October 24, 2025 16:50
c565085 to
61181f0
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
November 27, 2025 21:52
388c44f to
1605170
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
December 2, 2025 20:49
1605170 to
42b0d52
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
January 31, 2026 20:50
42b0d52 to
f206d78
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
February 26, 2026 11:18
f206d78 to
200fea3
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
March 15, 2026 00:46
986d3ab to
29c6f73
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
April 11, 2026 12:36
a916671 to
eb11855
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
April 19, 2026 14:27
2f7de09 to
74726dc
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
May 16, 2026 17:07
87cfe59 to
a21c618
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
May 25, 2026 17:42
a21c618 to
6d7990f
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
2 times, most recently
from
June 21, 2026 13:43
4af5b79 to
57759a1
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
July 13, 2026 23:34
57759a1 to
569a668
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
July 27, 2026 02:13
569a668 to
da3a31a
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
August 2, 2026 21:33
da3a31a to
cff4997
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
August 18, 2026 02:08
cff4997 to
664ccb9
Compare
renovate
Bot
force-pushed
the
renovate/verdaccio-verdaccio-6.x
branch
from
August 18, 2026 16:58
664ccb9 to
3b1b3b5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.11.0→6.10.0Release Notes
verdaccio/verdaccio (verdaccio/verdaccio)
v6.10.0Compare Source
Minor Changes
51c2733: Expose the optional legacy authentication cache for Verdaccio 6.x throughserver.legacyAuthCache.This feature is intended for performance-sensitive installations that still use legacy bearer tokens. When enabled, Verdaccio caches successful legacy token authentication results for a short period of time, so repeated requests using the same token do not need to run password verification through the authentication plugin every time. Concurrent requests for the same legacy token can also share the same in-flight authentication result.
The cache is disabled by default, so existing installations keep their current authentication behavior unless they explicitly opt in. Basic authentication is not cached. If the cache is enabled, changed or revoked credentials may remain valid until the cached entry expires.
Enable it in
config.yaml:Options:
enabled: enables the legacy token authentication cache. Default:false.ttlMs: time in milliseconds before a cached validation expires. Default:15000.maxEntries: maximum number of cached legacy tokens. Default:1000.See #6147 and the original 8.x backport in #6143.
v6.9.3Compare Source
Patch Changes
3c8f391: Reject wildcard characters in package and tarball path validation.ebc08ba: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):This dependency refresh includes
@verdaccio/package-filter13.2.0withexcludeDeprecatedsupport from #6142 by @jotadeveloper, based on the original work by @davidus27. It also includes the@verdaccio/ui-themeupdate containing the homepage action hover fix from #6135 by @pranshuchittora.@verdaccio/auth:8.1.1→8.1.2@verdaccio/config:8.2.1→8.2.2@verdaccio/core:8.2.1→8.2.2@verdaccio/hooks:8.1.2→8.1.3@verdaccio/loaders:8.1.1→8.1.2@verdaccio/local-storage-legacy:11.4.1→11.4.2@verdaccio/logger:8.1.1→8.1.2@verdaccio/middleware:8.1.1→8.1.2@verdaccio/package-filter:13.1.1→13.2.0@verdaccio/signature:8.1.1→8.1.2@verdaccio/tarball:13.1.1→13.1.2@verdaccio/ui-theme:9.0.0-next-9.23→9.0.0-next-9.26@verdaccio/url:13.1.1→13.1.2@verdaccio/utils:8.2.1→8.2.2verdaccio-audit:13.1.1→13.1.2verdaccio-htpasswd:13.1.1→13.1.2v6.9.2Compare Source
Patch Changes
297dc43: fix: apply package access controls to thestarredByUserendpointThe
GET /-/_view/starredByUserview did not enforce the configured packageaccess policy when listing a user's starred packages. Results are now filtered
through
auth.allow_access, so the response only includes packages therequesting client is authorized to see.
05917d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.22→9.0.0-next-9.23v6.9.0Compare Source
Minor Changes
b67a665: feat: require Node.js 22 as the minimum supported versionNode.js 22 or higher is now required (previously the CLI still accepted Node.js 18,
while
enginesalready demanded 20). The CLI refuses to start on older runtimes andenginesis set to>=22; Node.js 24 is the recommended version. CI, e2e, and smoketest matrices now cover Node.js 22, 24, and 26. Registry operators on Node.js 18 or 20
must upgrade the runtime before taking this release.
b67a665: feat: dual CJS + ESM build withexportsfield, migrate build from babel to vite 8Native ESM support. The package now ships both CommonJS (
build/**/*.js) and ESM(
build/**/*.mjs) outputs and declares anexportsfield, soimport { runServer } from 'verdaccio'resolves a real ES module instead of theCommonJS interop.
require('verdaccio')keeps working exactly as before. TheverdaccioCLI now runs on the ESM build, which means ESM-only dependencies can beloaded at runtime on every supported Node.js version.
Build toolchain. Babel has been replaced by vite 8 (rolldown) for transpilation;
type declarations are still emitted by TypeScript. This is not observable in the
registry behavior, but local workflows changed:
yarn startand thedebug/bootstrapscripts now use
tsxinstead ofbabel-node/@babel/register.Patch Changes
b67a665: fix(deps): update @verdaccio/hooks to 8.1.1Restores publish/unpublish webhook notifications when running on the ESM build: hooks
8.1.0 could not send them (the notify client failed silently on every call). The new
version replaces the frozen
got-cjsfork withgot15 loaded in a way that worksfrom both the ESM and CommonJS builds, and reports delivery failures based on the real
HTTP response status.
b67a665: fix(deps): update @verdaccio/* packages to the 2026-07-25 release batchUpdates all
@verdaccio/*andverdaccio-*dependencies (config 8.1.4, core 8.1.4,auth 8.0.6, middleware 8.0.7, htpasswd/audit 13.0.5, among others). Notably
@verdaccio/config8.1.4 moves tojs-yaml4.3.0, resolving the high-severityadvisory GHSA-52cp-r559-cp3m
(YAML merge-key chains forcing quadratic CPU consumption).
2969ec8: fix: migrate uplink/storage URL parsing to the WHATWG URL APIRemoves the
[DEP0169] DeprecationWarning: url.parse()printed at startup onNode.js 22+. The proxy and local-storage layers no longer use the legacy
url.parse()/
url.format()helpers; uplink URL validation, distfile filename extraction, and theremote-protocol tarball rewrite now go through the standardized
URLAPI. Behavior isunchanged for the absolute HTTP(S) URLs used in practice — the default HTTPS port
:443still normalizes to a match, and invalid uplink URLs are treated as not-valid instead of
being parsed leniently.
Because the WHATWG
URLconstructor throws on malformed input (unlike the lenient legacyurl.parse()), a misconfigured uplinkurlnow fails fast at startup with a clear,credential-redacted error, and a malformed
dist.tarballreturned by an upstream registryis skipped (with a warning) instead of aborting the package update. Uplink URL validation
also now compares the uplink's own port when deciding whether to ignore the default HTTPS
port, so an HTTPS uplink on a non-default port no longer matches a default-port tarball.
v6.8.0Compare Source
Minor Changes
962fba8: feat: add unpublish notification hooksPort of #5920 (ref #5328). The
notifywebhook now also fires when a package is unpublished entirely and when a single version (tarball) is removed, not only on publish. Notification templates can distinguish the event through the new{{ publishType }}(publish|unpublish) and{{ publishedPackage }}variables, and the{{ publisher }}object exposes onlyname,groupsandreal_groups, so the remote user auth token can never leak to the notification endpoint (via@verdaccio/hooks8.0.4).Patch Changes
f0684dc: fix: return 403 to client when uplink responds with 403 for tarball requestsPreviously, any non-200/404 response from an uplink (e.g. a security proxy blocking a package download) would result in a generic 500 error being returned to the client. This change propagates 403 responses from the uplink through to the client, including any error detail from the response body, so callers can distinguish authorization failures from other upstream errors.
3a84578: chore: refactor eslintb7a5db1: fix: rate limit and bound the npm search v1 endpointThe
/-/v1/searchendpoint now applies theuserRateLimitrate limiting middleware (matching the login, token and profile endpoints), clamps thesize(max 250, like the public npm registry) andfrom(max 10000) pagination parameters, and stops evaluating package access as soon as the requested page is filled instead of running an auth check over the entire result set. The clamped values are also what gets forwarded to uplink registries (the raw request URL is no longer passed through), so the bounds hold end-to-end. This prevents cheap anonymous requests from triggering unbounded full-catalog scans. As part of this, pagination is fixed: results were sliced withslice(from, size)instead ofslice(from, from + size), so pages beyond the first were wrong.Search results for local packages also emit npm-search-compatible maintainers (
{ username, email }) — npm 11 on Node 24 crashes rendering entries withoutusername(The "str" argument must be of type string. Received undefined) — and thepublisherfield is now populated from_npmUserwhen the publishing client provided it, falling back to the first maintainer, so the npm CLI shows the publishing user instead ofby ???.808d916: fix: pick the right uplink for tarballs and heal missing distfile recordsUplink selection. With several uplinks configured for a package, tarball downloads used the last uplink whose package pattern matched, even when the tarball url belongs to a different one, which could make downloads fail against registries that require authentication. The uplink is now selected by matching the tarball url: the
registryrecorded on the distfile wins, then the uplink whose url serves the file; when none matches, an autogenerated uplink with default settings is used. Single-uplink setups keep the previous behavior for tarballs hosted on another host (a CDN).Missing distfile records. Storages written by other verdaccio versions can carry cached versions without their
_distfilesrecords, which made those tarballs permanently return404 no such file available. The tarball location is now resolved from the version'sdist.tarballmetadata when the record is missing, and the record is restored when the tarball is cached.a2de1d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.20→9.0.0-next-9.21v6.7.4Compare Source
Patch Changes
0205c78: fix: run jwt middleware before middleware pluginsRegister the JWT middleware before middleware plugins are loaded so that
req.remote_user(anonymous by default) is available inside a plugin'sregister_middlewares. The API router keeps its own JWT middleware behind aguard so it is not executed twice.
Backport of #5697
Closes #5167
v6.7.3Compare Source
Patch Changes
f8fdfc2: fix: enforce generated npm token metadataGenerated npm tokens (
POST /-/npm/v1/tokens) stored theirreadonlyandcidr_whitelistrestrictions but never enforced them, and deleting a token didnot revoke it for the package APIs. A token marked read-only or pinned to a CIDR
range could still publish packages and change dist-tags, and a deleted token
remained usable.
Generated tokens now embed a server-issued key (in the JWT claim, or in the
encrypted legacy AES payload) and a new
enforceGeneratedTokenMetadatamiddleware looks that key up on each request, rejecting the token when it is
missing/revoked, used outside its CIDR whitelist, or used for a write while
read-only. Enforcement applies to both AES and JWT API-token modes.
Note: tokens issued before upgrading carry no key and are not retroactively
constrained — regenerate them to apply the restrictions.
be80623: fix: allow npm token create without readonly/cidr_whitelistnpm token createin npm >= 11 (and the npm 12 prereleases) rewrote therequest body: it no longer sends
readonlyand only sendscidr_whitelistwhen
--cidris passed. ThePOST /-/npm/v1/tokensendpoint required both,so modern npm clients failed with
422 the parameters are not valid.The endpoint now defaults
readonlytofalseandcidr_whitelistto[]when they are absent, while still rejecting values of the wrong type.
75c85d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.19→9.0.0-next-9.20d5e5332: chore: update dependenciesUpdates runtime dependencies
@verdaccio/ui-theme(9.0.0-next-9.19) andsemver(7.8.2), along with development dependencies: Babel7.29.7,@changesets/cli2.31.0, ESLint10.4.1, Vitest4.1.8, Cypress15.16.0,Prettier
3.8.3,@verdaccio/test-helper4.0.4,@verdaccio/eslint-config13.1.2, and assorted type definitions.v6.7.2Compare Source
Patch Changes
a89aca1: chore: fix unit testa28cf71: chore: add missing types #5889 by @mbtoolsv6.7.1Compare Source
Patch Changes
a75f9bb: chore: refactor docker publish pipelinev6.6.0Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.5.2...v6.6.0
v6.5.2Compare Source
6.5.2 (2026-04-19)
Bug Fixes
v6.5.1Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.5.0...v6.5.1
v6.5.0Compare Source
Features
Bug Fixes
v6.4.0Compare Source
Features
Package Filter Plugins (#5786, #5548) by @vsugrob, @pyhp2017 @juanpicado
@verdaccio/package-filteris a built-in plugin that intercepts package metadata from uplinks and removes versions matching configurable rules. With no rules configured, it acts as a no-op passthrough.Block a compromised package version
Block an entire malicious scope
Quarantine recently published versions
Hide versions published less than 7 days ago, giving time for review before adoption:
Freeze registry to a point in time
Only serve versions published before a specific date:
Whitelist trusted packages within blocked rules
Replace instead of remove
Substitute a blocked version with the nearest older safe version, useful when removing it would break transitive dependencies:
Full example
Bug Fixes
eabde8c@juanpicadopseudoRandomByteswithrandomBytesfromnode:cryptoeabde8c@juanpicadoFull Changelog: verdaccio/verdaccio@v6.3.2...v6.4.0
v6.3.2Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.3.1...v6.3.2
v6.3.1Compare Source
latestimageFull Changelog: verdaccio/verdaccio@v6.3.0...v6.3.1
v6.2.9Compare Source
Full Changelog: verdaccio/verdaccio@v6.2.8...v6.2.9
latestand semantic version tagsReference: https://redirect.github.com/orgs/verdaccio/discussions/5582
v6.2.5Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.2.4...v6.2.5
v6.2.4Compare Source
What's Changed
VERDACCIO_ADDRESSEnvironment Variable for DockerYou can now set the
VERDACCIO_ADDRESSenvironment variable to control Verdaccio’s network bind address.0.0.0.0), IPv6 ([::]), or a specific interface.Example:
docker run -e VERDACCIO_ADDRESS=0.0.0.0 ... docker run -e VERDACCIO_ADDRESS='[::]' ...More info at : https://verdaccio.org/docs/env/
Full Changelog: verdaccio/verdaccio@v6.2.3...v6.2.4
v6.2.3Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.2.2...v6.2.3
v6.2.2Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.2.1...v6.2.2
v6.2.1Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.2.0...v6.2.1
v6.2.0Compare Source
What's Changed
also includes improvements from master branch from @mbtools (I will expand on this later)
New Contributors
Full Changelog: verdaccio/verdaccio@v6.1.6...v6.2.0
v6.1.6Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.1.5...v6.1.6
v6.1.5Compare Source
What's Changed
@mbtools @juanpicado
Full Changelog: verdaccio/verdaccio@v6.1.4...v6.1.5
v6.1.4Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.1.3...v6.1.4
v6.1.3Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.1.2...v6.1.3
v6.1.2Compare Source
6.1.2 (2025-04-01)
Bug Fixes
v6.1.1Compare Source
6.1.1 (2025-03-30)
Reported Bugs (fixed at v6.1.2)
Bug Fixes
v6.1.0Compare Source
Reported bugs from this version (fixed at v6.1.2)
What's Changed
Big thanks to @mbtools for the last three months of remarkable improvements (which are behind the core dev updates, mostly on the master branch)
Improvements
Improved logging for plugins
Before
New
Other improvements
Full Changelog: verdaccio/verdaccio@v6.0.5...v6.1.0
v6.0.5Compare Source
What's Changed
5a91448) @kuoruan139861e) @juanpicadoFull Changelog: verdaccio/verdaccio@v6.0.4...v6.0.5
v6.0.4Compare Source
v6.0.4
What's Changed
Full Changelog: verdaccio/verdaccio@v6.0.3...v6.0.4
v6.0.3Compare Source
What's Changed
Full Changelog: verdaccio/verdaccio@v6.0.2...v6.0.3
v6.0.2Compare Source
6.0.2 (2024-11-17)
What's Changed
b6ea32cchore: adderrorto log level enum (#4943)4f5802cchore: add unpublish to package access config (#4941)e308fbbchore: move agent_options to config (#4942)80e4cb8chore: add info to log when local storage is used (#4948)e3c55f0chore: encode parts of URL (#4922)58e0d95fix(middleware): error 404 when getting scoped tarballs (#4913) @mbtoolsFull Changelog: verdaccio/verdaccio@v6.0.1...v6.0.2
v6.0.1Compare Source
6.0.1 (2024-10-16)
Bug Fixes
v6.0.0Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.