Skip to content

fix!: do not switch to git+ssh for https repository links - #434

Merged
owlstronaut merged 1 commit into
npm:mainfrom
oldium:fix/git-https
Apr 29, 2026
Merged

owlstronaut merged 1 commit into
npm:mainfrom
oldium:fix/git-https

Conversation

@oldium

@oldium oldium commented Oct 27, 2025 •

Copy link
Copy Markdown
Contributor

BREAKING CHANGE: git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.

When the URL explicitly contains https, do not try to switch to ssh. This change is necessary for npm to retain the protocol, please see the link and the referenced issues here and here reporting problems when using ssh instead of requested https.

References

Relates to npm/cli#8703

@oldium
oldium requested a review from a team as a code owner October 27, 2025 15:51
@wraithgar wraithgar changed the title bugfix: do not switch to git+ssh for https repository links fix: do not switch to git+ssh for https repository links Nov 13, 2025
When the URL explicitly contains https, do not try to switch to ssh. This
change is necessary for [npm][3] to retain the protocol, please see the
link and the referenced issues [here][1] and [here][2] reporting problems
when using ssh instead of requested https.

[1]: npm/cli#2610
[2]: npm/cli#4305
[3]: npm/cli#8703

Signed-off-by: Oldřich Jedlička <[email protected]>
@oldium

oldium commented Nov 22, 2025

Copy link
Copy Markdown
Contributor Author

Rebased to latest main

@wraithgar

Copy link
Copy Markdown
Contributor

This kind of change is one that is likely going to need to be a semver major one, out of an abundance of caution. It looks good as-is, but historically this kind of change is pretty disruptive in places we don't expect.

We will keep this PR open, and I have added it to the future changes tracking issue

@wraithgar wraithgar added the semver:major backwards-incompatible breaking changes label Feb 24, 2026
@owlstronaut owlstronaut changed the title fix: do not switch to git+ssh for https repository links fix!: do not switch to git+ssh for https repository links Apr 29, 2026
@owlstronaut
owlstronaut merged commit 6d160c1 into npm:main Apr 29, 2026
0 of 2 checks passed
@github-actions github-actions Bot mentioned this pull request Apr 29, 2026
owlstronaut pushed a commit that referenced this pull request Jun 15, 2026
🤖 I have created a release *beep* *boop*
---


## [22.0.0](v21.5.0...v22.0.0)
(2026-06-15)
### ⚠️ BREAKING CHANGES
* `pacote` now supports node `^22.22.2 || ^24.15.0 || >=26.0.0`
* git specs using the `https` or `git+https` protocol now resolve to
`git+https` URLs instead of being switched to `git+ssh`. Shortcut specs
(e.g. `github:user/repo`, `user/repo`) and `git+ssh`/`git://` specs are
unchanged.
### Features
*
[`09316f5`](09316f5)
[#504](#504) bump to new node engine
range (@owlstronaut)
*
[`2ab74b0`](2ab74b0)
[#497](#497) strip patchedDependencies
from the packed package.json (#497) (@manzoorwanijk)
*
[`66e7ea7`](66e7ea7)
[#487](#487) forward globalIgnoreFile
option to npm-packlist (@ljharb)
### Bug Fixes
*
[`ce804fb`](ce804fb)
[#498](#498) avoid ReDoS in addGitSha
committish stripping (#498) (@owlstronaut)
*
[`1f5f131`](1f5f131)
[#494](#494) pass --global=false when
preparing git dependencies (@owlstronaut)
*
[`e0af7f6`](e0af7f6)
[#486](#486) respect ignoreScripts
option for git dependencies (@owlstronaut)
*
[`12c8c8f`](12c8c8f)
[#481](#481) fall back to git clone
when tarball response is not a valid archive (@babyhuey)
*
[`61f065a`](61f065a)
[#481](#481) use statusCode instead of
constructor name for tarball fallback in git fetcher (@j1mb0-1)
*
[`6d160c1`](6d160c1)
[#434](#434) do not switch to git+ssh
for https repository links (#434) (@oldium)
### Dependencies
*
[`371e8b0`](371e8b0)
[#504](#504) `[email protected]`
*
[`b68c6c2`](b68c6c2)
[#504](#504) `[email protected]`
*
[`57793ab`](57793ab)
[#504](#504) `[email protected]`
*
[`33eacc9`](33eacc9)
[#504](#504)
`[email protected]`
*
[`a131916`](a131916)
[#504](#504)
`[email protected]`
*
[`2b03527`](2b03527)
[#504](#504) `[email protected]`
*
[`5f8ad42`](5f8ad42)
[#504](#504) `[email protected]`
*
[`ee3b96d`](ee3b96d)
[#504](#504) `[email protected]`
*
[`033f655`](033f655)
[#504](#504)
`@npmcli/[email protected]`
*
[`ddcc738`](ddcc738)
[#504](#504)
`@npmcli/[email protected]`
*
[`6a28eb2`](6a28eb2)
[#504](#504)
`@npmcli/[email protected]`
*
[`5879416`](5879416)
[#504](#504)
`@npmcli/[email protected]`
*
[`41ea727`](41ea727)
[#504](#504) `@npmcli/[email protected]`
### Chores
*
[`3fc5fd4`](3fc5fd4)
[#504](#504)
`@npmcli/[email protected]` (@owlstronaut)
*
[`7350ab8`](7350ab8)
[#504](#504) `[email protected]`
(@owlstronaut)
*
[`c7c7d7f`](c7c7d7f)
[#504](#504) template-oss-apply
(@owlstronaut)
*
[`e9ac85e`](e9ac85e)
[#501](#501) template-oss-apply
(@owlstronaut)
*
[`e184356`](e184356)
[#501](#501) `[email protected]`
(@owlstronaut)
*
[`644ebb6`](644ebb6)
[#479](#479) template-oss-apply
(@owlstronaut)
*
[`ee64bea`](ee64bea)
[#479](#479)
`@npmcli/[email protected]` (@owlstronaut)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
owlstronaut pushed a commit to npm/cli that referenced this pull request Jun 19, 2026
This prevents changing URLs from `https` and `git+https` into `git+ssh`,
but keeps the fall-back to `git+ssh` when the protocol is not specified.

The change in [pacote](npm/pacote#434) is
necessary in order to have this fully working.

## References
Supersedes #5256
Blocked by npm/pacote#434
Fixes #4305
Fixes #2610

Signed-off-by: Oldřich Jedlička <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver:major backwards-incompatible breaking changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants