npm / npm/cli

[BUG] npm install doesn't report post-install script warning when root project has prepare hook that fails

Open
#9,943 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

allowScripts Bug cmd:install ws:arborist
Dominant language
JavaScript
Stars
10.1k
Forks
4.7k
Avg merge
2d 2h
Merged PRs (30d)
19

Description

Is there an existing issue for this?
  • I have searched the existing issues
This issue exists in the latest npm version
  • I am using the latest npm
This is not just a request to bump a dependency for a CVE
  • This is not solely a request to bump a dependency for a CVE
Current Behavior

When I run npm install in the directory of an existing project, some post-install scripts are skipped in NPM 12, while they weren't in previous versions. This is OK, I understand it's an intentional change. However - if the root project has a prepare script, that fails because the post-install scripts were skipped - then the skipping is totally and completely silent. There's no warning in the command-line output, which makes no mention of the fact that some steps were skipped prior to running the root project prepare script, and even if you look in the npm debug log, there's no trace of the skipped script.

On the other hand, if you run npm install <specific package>, then a warning is printed. Or if you remove the prepare script from the root package.json. The warning isn't printed, in the case that the <specific package> is a dependency in the project and it has a prepare script that fails.

Expected Behavior

If a post-install script is skipped, this fact should always be reported. It should double especially always be reported if skipping the post-install script causes later errors. Especially because any later errors, after a post-install script is skipped, are likely to be bizarrely incomprehensible stack traces from transitive dependencies. See below for an example.

Steps To Reproduce

NPM 12 is critical here.

% git clone https://github.com/sensepost/objection.git --revision d9d50c206d5ae7b7aa5c5b9cfa3caaad6b4be66d
% cd objection/agent
% npm install
npm warn deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated glob@7.2.3: Glob versions prior to v9 are no longer supported
npm warn deprecated tslint@6.1.3: TSLint has been deprecated in favor of ESLint. Please see https://github.com/palantir/tslint/issues/4534 for more information.
npm notice run objection@0.0.0 prepare
npm notice run npm run build
npm notice run objection@0.0.0 build
npm notice run frida-compile src/index.ts -o ../objection/agent.js -T none
/tmp/objection/agent/node_modules/bindings/bindings.js:126
  err = new Error(
        ^

Error: Could not locate the bindings file. Tried:
 → /tmp/objection/agent/node_modules/frida/build/frida_binding.node
 → /tmp/objection/agent/frida_binding.node
    at bindings (/tmp/objection/agent/node_modules/bindings/bindings.js:126:9)
    at file:///tmp/objection/agent/node_modules/frida/build/src/frida.js:6:17
    at ModuleJob.run (node:internal/modules/esm/module_job:569:25)
    at async node:internal/modules/esm/loader:650:26
    at async asyncRunEntryPointWithESMLoader (node:internal/modules/run_main:101:5) {
  tries: [
    '/tmp/objection/agent/node_modules/frida/build/frida_binding.node',
    '/tmp/objection/agent/frida_binding.node'
  ]
}

Node.js v26.8.1
npm error code 1
npm error path /tmp/objection/agent
npm error command failed
npm error command sh -c npm run build
npm error A complete log of this run can be found in: /home/raxod502/.npm/_logs/2026-09-03T03_54_18_269Z-debug-0.log

https://github.com/sensepost/objection/pull/819

Environment
  • npm: 12.0.2
  • Node.js: 26.8.1
  • OS Name: Arch Linux
  • System Model Name: System 76 Oryx Pro 6
  • npm config:
; "env" config from environment

update-notifier = false

; node bin location = /usr/bin/node
; node version = v26.8.1
; npm local prefix = /tmp/objection/agent
; npm version = 12.0.2
; cwd = /tmp/objection/agent
; HOME = /home/raxod502
; Run `npm config ls -l` to show all defaults.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue with npm 12.0.2 using the objection/agent example and the npm install entry point. Trace the install lifecycle around skipped post-install scripts and the root prepare hook, then add regression coverage showing that a warning is emitted before the later failure.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, nodejs
Domain
cli, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.