npm: arborist-v9.8.0 Release

Release date:
June 11, 2026
Previous version:
arborist-v9.7.0 (released May 27, 2026)
Magnitude:
1,623 Diff Delta
Contributors:
5 total committers
Data confidence:
Commits:

29 Features Released with arborist-v9.8.0

Top Contributors in arborist-v9.8.0

github-actions[bot]
JamieMagee
owlstronaut
manzoorwanijk
reggi

Directory Browser for arborist-v9.8.0

We haven't yet finished calculating and confirming the files and directories changed in this release. Please check back soon.

Release Notes Published

9.8.0 (2026-06-11)

Features

  • ae8ac4e #9534 add min-release-age-exclude config (@JamieMagee, @caseyjhol)
  • 8ff3e48 #9483 allowScripts tooling and inBundle hardening (#9483) (@github-actions[bot], @JamieMagee) ### Bug Fixes
  • fc5573a #9530 keep nested file: deps and re-resolve changed git refs (#9530) (@github-actions[bot], @owlstronaut)
  • b13ee4d #9511 arborist: honor allow-remote=root for root-direct remote tarballs (#9511) (@github-actions[bot], @manzoorwanijk)
  • 66408d7 #9500 arborist: apply registry-tarball allow-remote exemption in linked strategy (#9500) (@github-actions[bot], @manzoorwanijk)
  • 4fa81df #9497 recognize allowScripts for local link targets (#9497) (@github-actions[bot], @cyphercodes, @cyphercodes)
  • 95cf2e9 #9489 validate registry path for allow-remote tarballs (@Abhinav-143x)
  • 869cb9a #9485 arborist: link meta-only optional peers in linked strategy (@manzoorwanijk)
  • d41a9e3 #9484 arborist: clean up orphaned scoped store entries in linked strategy (@manzoorwanijk)
  • 39d034d #9455 sanitize package name in linked-strategy path construction (@owlstronaut)
  • d59c964 #9451 reject path traversal entries when inflating dependency shrinkwraps (@owlstronaut)
  • c9045d5 #9429 arborist: read install scripts from disk on lockfile installs instead of a sentinel (@JamieMagee)