Skip to content

Support npm content-addressed tarball URLs - #406

Merged
andrew merged 1 commit into
mainfrom
fix/npm-metadata-tarballs
Oct 4, 2026
Merged

andrew merged 1 commit into
mainfrom
fix/npm-metadata-tarballs

Conversation

@andrew

@andrew andrew commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Registries such as GitHub Packages publish tarball URLs ending in a content hash, which the proxy cannot parse as a package version. Rewrite these to conventional proxy filenames and resolve the original dist.tarball URL from upstream metadata on an artifact cache miss.

Reuse the metadata fetch for cooldown checks, preserve signed query strings, and require tarball URLs to stay within the configured registry origin and base path. Missing or unusable metadata falls back to the conventional download URL. Cached artifacts remain available without fetching metadata when the publish time is already stored or cooldown is disabled.

Replaces #238 and addresses its outstanding review findings.

Copilot AI balanced review requested due to automatic review settings October 4, 2026 17:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@andrew
andrew force-pushed the fix/npm-metadata-tarballs branch from 315fc5b to 34985b5 Compare October 4, 2026 17:23
@andrew
andrew merged commit 8d6c5ca into main Oct 4, 2026
9 checks passed
@andrew
andrew deleted the fix/npm-metadata-tarballs branch October 4, 2026 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants