# @npmcli/redact

> Redact sensitive npm information from output

Latest version **5.0.0** (published 2026-05-08) · ISC license · 0 weekly downloads

## Install

```sh
npm install @npmcli/redact
pnpm add @npmcli/redact
yarn add @npmcli/redact
bun add @npmcli/redact
```

## Health

**Score 60/100 (C)** — status: active.

Positive: esm support; no vulnerabilities; has provenance; high maintenance score.

Warnings: low downloads; no types.

## Facts

| | |
|---|---|
| Version | 5.0.0 |
| Published | 2026-05-08 |
| First published | 2024-04-03 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | ESM + CommonJS |
| Node | ^22.22.2 \|\| ^24.15.0 \|\| >=26.0.0 |
| Dependencies | 0 |
| Unpacked size | 16.5 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 5 |
| Author | GitHub Inc. |
| Maintainers | saquibkhan, npm-cli-ops, reggi, owlstronaut |

## Links

- npm: https://www.npmjs.com/package/@npmcli/redact
- Repository: https://github.com/npm/redact
- Homepage: https://github.com/npm/redact#readme
- Issues: https://github.com/npm/redact/issues
- npm.io page: https://npm.io/package/@npmcli/redact

## Recent versions

- 5.0.0 (latest) — 2026-05-08
- 4.0.0 — 2025-10-22
- 3.2.2 — 2025-05-05
- 3.2.1 — 2025-05-02
- 3.2.0 — 2025-04-21
- 3.1.1 — 2025-01-29
- 3.1.0 — 2025-01-29
- 3.0.0 — 2024-09-25
- 2.0.1 — 2024-06-05
- 2.0.0 — 2024-04-26
- 1.1.0 — 2024-04-03
- 1.0.0 — 2024-04-03
- 0.0.0 — 2024-04-03

## README

# @npmcli/redact

Redact sensitive npm information from output.

## API

This will redact `npm_` prefixed tokens and UUIDs from values.

It will also replace passwords in stringified URLs.

### `redact(string)`

Redact values from a single value

```js
const { redact } = require('@npmcli/redact')

redact('https://user:pass@registry.npmjs.org/')
// https://user:***@registry.npmjs.org/

redact(`https://registry.npmjs.org/path/npm_${'a'.repeat('36')}`)
// https://registry.npmjs.org/path/npm_***
```

### `redactLog(string | string[])`

Redact values from a string or array of strings.

This method will also split all strings on `\s` and `=` and iterate over them.

```js
const { redactLog } = require('@npmcli/redact')

redactLog([
  'Something --x=https://user:pass@registry.npmjs.org/ foo bar',
  '--url=http://foo:bar@registry.npmjs.org',
])
// [
//   'Something --x=https://user:***@registry.npmjs.org/ foo bar',
//   '--url=http://foo:***@registry.npmjs.org/',
// ]
```

---
_Source: https://npm.io/package/@npmcli/redact · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
