Is there an existing issue for this?
- I have searched the existing issues
This issue exists in the latest npm version
- I am using the latest npm
This is not just a request to bump a dependency for a CVE
- This is not solely a request to bump a dependency for a CVE
Current Behavior
Here is the log of the latest npm install. The way to mitigate is to use --no-audit but I would want to avoid doing that.
abhinasu-mac:nodejs abhinasu$ npm i --verbose
npm verbose cli /opt/homebrew/Cellar/node/24.1.0/bin/node /opt/homebrew/bin/npm
npm info using npm@11.3.0
npm info using node@v24.1.0
npm verbose title npm i
npm verbose argv "i" "--loglevel" "verbose"
npm verbose logfile logs-max:10 dir:/Users/abhinasu/.npm/_logs/2026-09-04T04_11_41_471Z-
npm verbose logfile /Users/abhinasu/.npm/_logs/2026-09-04T04_11_41_471Z-debug-0.log
npm http fetch POST 200 https://registry.npmjs.org/-/npm/v1/security/advisories/bulk **173178ms**
up to date, audited 69 packages in 3m
27 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
npm verbose cwd /Users/abhinasu/Developer/helloworld/nodejs
npm verbose os Darwin 24.6.0
npm verbose node v24.1.0
npm verbose npm v11.3.0
npm verbose exit 0
npm info ok
Expected Behavior
No response
Steps To Reproduce
- In this environment...
- With this config...
- Run 'npm i'
- See error...
No error but takes too long
Environment
- npm:
- Node.js:
- OS Name: Mac/Linux
- System Model Name:
- npm config: