Summary
The CITGM integration installs JSONStream's dependency tree without configuring the Git-dependency policy required by npm 12. Both Node 22 and Node 23 stop with EALLOWGIT while resolving a Git dependency. These are two occurrences of one fixture-policy mismatch.
Affected run
Branch: latest, commit c039090578a5b21a1aa3aba9c96e199feaf1823a, npm 12.1.0.
Workflow: https://github.com/npm/cli/actions/runs/35779328486
The corresponding jobs in the npm 11.20.0 release run passed.
Failure
npm error code EALLOWGIT
npm error Fetching packages of type "git" have been disabled
npm error Refusing to fetch "fomatto@git://github.com/BonsaiDen/Fomatto.git#468666f600b46f9067e3da7200fd9df428923ea6"
This occurs during:
npm install --no-audit --no-fund
The source archive has already been downloaded and extracted. Installation is blocked by policy before the package tests execute.
Root cause
npm 12 intentionally changed allow-git and allow-remote to default to none, documented in the npm 12.0.0 breaking changes.
JSONStream's dependency tree requires the Git-hosted fomatto package, but the integration does not provide a fixture-specific opt-in or remove that legacy dependency requirement. npm is enforcing its configured policy.
The failure also occurs on supported Node 22. It must not be attributed to the separate unsupported Node 23 matrix entry.
Proposed resolution
Review the intended fixture dependency tree and either eliminate the legacy Git dependency through a suitable fixture update or explicitly configure the minimum Git policy necessary for this trusted integration case. Preserve npm's production defaults and avoid blanket opt-ins across unrelated CITGM packages.
The npm/cli matrix generator consumes CITGM metadata, so the solution must identify whether the fixture metadata belongs upstream in CITGM or whether npm/cli needs integration-specific handling. Changes to generated npm/cli workflows must also update their templates.
Acceptance criteria
- The intended JSONStream dependency tree installs on supported npm 12 runtimes and its tests actually execute.
- The same integration remains compatible with the v11 branch.
- The scope and rationale of any Git-dependency opt-in are explicit.
- Any subsequent failure is investigated on its own evidence rather than treating removal of
EALLOWGIT as proof that the entire job is fixed.
Scope boundary
This is independent of #10016, #10020, the Node 23 engine mismatch, and the native-build flag forwarding failure. Allowing Git dependencies does not make --build-from-source a valid npm 12 CLI flag.
Summary
The CITGM integration installs JSONStream's dependency tree without configuring the Git-dependency policy required by npm 12. Both Node 22 and Node 23 stop with
EALLOWGITwhile resolving a Git dependency. These are two occurrences of one fixture-policy mismatch.Affected run
Branch:
latest, commitc039090578a5b21a1aa3aba9c96e199feaf1823a, npm12.1.0.Workflow: https://github.com/npm/cli/actions/runs/35779328486
The corresponding jobs in the npm 11.20.0 release run passed.
Failure
This occurs during:
The source archive has already been downloaded and extracted. Installation is blocked by policy before the package tests execute.
Root cause
npm 12 intentionally changed
allow-gitandallow-remoteto default tonone, documented in the npm 12.0.0 breaking changes.JSONStream's dependency tree requires the Git-hosted
fomattopackage, but the integration does not provide a fixture-specific opt-in or remove that legacy dependency requirement. npm is enforcing its configured policy.The failure also occurs on supported Node 22. It must not be attributed to the separate unsupported Node 23 matrix entry.
Proposed resolution
Review the intended fixture dependency tree and either eliminate the legacy Git dependency through a suitable fixture update or explicitly configure the minimum Git policy necessary for this trusted integration case. Preserve npm's production defaults and avoid blanket opt-ins across unrelated CITGM packages.
The npm/cli matrix generator consumes CITGM metadata, so the solution must identify whether the fixture metadata belongs upstream in CITGM or whether npm/cli needs integration-specific handling. Changes to generated npm/cli workflows must also update their templates.
Acceptance criteria
EALLOWGITas proof that the entire job is fixed.Scope boundary
This is independent of #10016, #10020, the Node 23 engine mismatch, and the native-build flag forwarding failure. Allowing Git dependencies does not make
--build-from-sourcea valid npm 12 CLI flag.