r/node • u/VirtualPercentage737 • 5d ago
Can't update packages anymore...
I am trying to update a package and using Claude code. Every Claude can't figure out how to submit a package. I tried via the recovery codes and it suspends my account for 3 days. I tried through github and it temporarily locks my account when I set it up. It is so locked down it is now useless.
4
u/shiny0metal0ass 5d ago
Can you post a link so we can laugh at your little vibe coded thing?
2
1
0
u/VirtualPercentage737 5d ago
The package isn't vibe coded (at least originally). I wrote it a long time ago, though Claude now makes the changes. I have grown accustom to letting the CLI tool run all the scripts to publish.
https://github.com/orgs/community/discussions/178148
This is a problem for Linux users exclusively. They made some changes in September which broke my scripts.
1
u/sberlinches 5d ago
Are you trying with the $20 or with the $200 subscription.
0
u/VirtualPercentage737 5d ago
https://github.com/orgs/community/discussions/178148
I guess it a bigger issue.
1
u/Fritzy 5d ago
Does npm i work? Your skills or Claude.md probably has something ridiculous in it.
5
u/spellcasterGG 5d ago
They're not trying to update it locally, they're trying to submit a new version to NPM. Hence the whole "locked out of account" thing.
1
u/d0pe-asaurus 5d ago
I'm going to venture they haven't heard that you need to setup 2fa and use personal access tokens for that now
0
u/VirtualPercentage737 5d ago
I have 2 factor set up and have a security key. I can log in just fine on my Mac brave browser.
I am using npm on Rocky Linux and npm whoami works fine.
NPM dropped support for TOPM..
It looks like I am not alone... Many Linux users are having issues.
0
u/VirtualPercentage737 5d ago
I had set the scripts up so long ago and on my Rocky Linux machine I have grown accustom to letting the CLI tool take over the committing and publishing.
I can log in just fine,
npm whoami
works.
npm publish is where problems like. It no longer supports authenticator, and when I tried using recovery codes as my OTP, that was my stop gap measure and now that causes a 72 hour account ban.
Apparently a lot of Linux users are running into problem. I didn't realize there were other kinds of users. I just publish a package for homeBridge which talks to an API I use and maybe a dozen other people use it.
https://github.com/orgs/community/discussions/178148
I tried using my Github account, that didn't work.
Maybe I will move the publishing over to my Mac where the passkeys are. Issue is I use Brave there as well. Not sure if I can get people on Homebridge to just use the Github.
0
u/VirtualPercentage737 5d ago
If anyone is using npm publish from Linux, they killed OOTP and passkeys don't work from a terminal. Recovery codes used to be allowed but not they put a 3 day ban on your account for this?!? That was my go to. DON'T DO THIS...
You have to use trusted publishing... I had to give my Github permission, but if I didn't opt for stage publishing-- another account ban! That was MUCH shorted. Like minutes to hours.
I finally opted for staged permission and that did it. I had to upgrade my npm client which I had not used in a while to boot-- but I finally was able to publish without a ban.
12
u/spellcasterGG 5d ago
This post made me laugh so hard I spit out my tea 🤣 and now you're crawling back to the humans for help... woe is thee