What verdaccio/verdaccio shipped
Written by FoxPlug from public releases; not affiliated with Verdaccio. An automatic summary of the public release, pull request and commit data of github.com/verdaccio/verdaccio. Verdaccio did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Verdaccio 9.0.0-next-9.33 released with version updates across the monorepo [6]. Release
- Restored programmatic exports including default export and configuration helpers that were dropped from the verdaccio package [12]. Pull request #6286
- Fixed legacy storage adapter search to properly filter packages by query instead of returning the entire catalogue [17]. Pull request #6279
- Fixed uplink cache refresh when receiving 304 Not Modified responses to prevent unnecessary revalidation on every request [18]. Pull request #6276
- Fixed search v1 responses to return ISO 8601 formatted timestamps instead of textual GMT dates [23]. Pull request #6263
- Added validation of versions before merging search results to prevent HTTP 500 errors from malformed uplink versions [26]. Pull request #6264
- Added server.hidePingLogs setting to suppress successful ping request logs while keeping failed ping logs visible [19]. Pull request #6192
- Prevented logging of cancelled uplink searches when clients close connections [21]. Pull request #6268
- Removed unused search-indexer workspace and its Orama dependency from the project [13]. Pull request #6285
- Added E2E UI tests matching the master branch setup with 13 Cypress specs and TypeScript 7 support [15]. Pull request #6282
Why it matters
This week focused on fixing critical bugs in search functionality, cache handling, and data format compliance that affect users upgrading from earlier versions. Programmatic exports were restored to maintain backward compatibility for library consumers. Infrastructure improvements ensure better test coverage and cleaner maintenance of the codebase.
Changelog entry
- feat: restore the programmatic exports including default export and configuration helpers [#6286] Pull request #6286
- fix(storage): pass the search query through the legacy adapter [#6279] Pull request #6279
- fix(store): refresh the uplink cache when an uplink replies 304 [#6276] Pull request #6276
- fix(api): return ISO timestamp in search responses [#6263] Pull request #6263
- fix(search): validate versions before merging search results [#6264] Pull request #6264
- fix(proxy): preserve original uplink search errors [#6265] Pull request #6265
- feat(middleware): add server.hidePingLogs to suppress successful ping logs [#6192] Pull request #6192
- fix(proxy): avoid logging cancelled uplink searches [#6268] Pull request #6268
- chore: remove unused search indexer [#6285] Pull request #6285
- test(e2e): add the E2E UI job, matching master [#6282] Pull request #6282
Verdaccio 9.0.0-next-9.33 ships search fixes, restored programmatic exports, improved cache handling, and E2E UI test coverage. Upgrading from 7.x now works as expected.
Verdaccio 9.0.0-next-9.33 is out with significant improvements for users and maintainers. We restored programmatic exports to fix breaking changes when upgrading from 7.x, fixed search filtering to properly handle package queries, and corrected timestamp formats in API responses. Cache handling for uplinks was improved to prevent unnecessary revalidation. We also added E2E UI test coverage and removed unused dependencies as part of ongoing maintenance efforts.
Week of September 14, 2026
What shipped
- Package filter now supports glob patterns for scope and package rules, allowing more flexible allow and block configurations. Pull request #5872
- Server CORS options are now configurable via standard CorsOptions, with sensible defaults preserved when omitted. Pull request #6255
- Fixed npm publish failures on 6.x by registering body parser before JWT middleware to handle request sizes correctly. Pull request #6249
- Logger now properly cleans up failed file destination initialization and reports errors to stderr without terminating the registry. Pull request #6260
- Express bumped to 4.22.3 across middleware packages to address query-string DoS vulnerabilities in qs 6.15.x. Pull request #6257
- Configuration path resolution on Windows fixed by using process.env.HOME when available instead of relying solely on os.homedir. Pull request #6247
- Windows CI pipeline added with basic build and test workflow for Node.js 24, triggered manually. Pull request #6248
- Plugin loader test coverage improved with additional cases for ES modules and default exports. Pull request #6238
- Development dependencies updated to clear 25 high-severity audit findings and bump e2e-ui to 2.7.0. Pull request #6256
Why it matters
This week focused on fixing critical issues in publishing workflows and security vulnerabilities while expanding configuration flexibility. The glob pattern support and CORS options provide developers with finer control over package filtering and cross-origin behavior, while the Windows CI support and various bug fixes improve reliability across platforms.
Changelog entry
- feat(package-filter): support glob patterns for scope and package rules Pull request #5872
- feat(server): allow configuring CORS options with standard CorsOptions type Pull request #6255
- fix: register body parser before JWT middleware on 6.x to fix npm publish failures Pull request #6249
- fix(logger): properly handle and clean up file destination initialization errors Pull request #6260
- fix: bump express to 4.22.3 to address qs DoS vulnerabilities Pull request #6257
- fix(config): use process.env.HOME for path resolution on Windows Pull request #6247
- chore: add Windows CI pipeline for Node.js 24 Pull request #6248
- chore(loader): improve plugin loader test coverage for ES modules Pull request #6238
This week: glob patterns for package filters, configurable CORS, npm publish fix on 6.x, Windows CI support, and security updates to address query-string DoS vulnerabilities.
Verdaccio shipped improvements across multiple fronts this week. Package filters now support glob patterns for more flexible rules, CORS options are configurable via standard types, and a critical npm publish bug on 6.x was fixed. Security updates address query-string DoS vulnerabilities, Windows CI was added, and configuration handling improved. These changes enhance both developer control and platform stability.