镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Npm command does not work Node.js >= 22 with "AllSigned" PowerShell policy when installing because npm.ps1 is not digitally signed. #60075

Description

@pronitsateli731

Version

22.20.0

Platform

Microsoft Windows NT 10.0.26100.0 x64

Subsystem

No response

What steps will reproduce the bug?

  1. Set the PowerShell execution policy to "AllSigned", for example by Set-ExecutionPolicy AllSigned -Scope LocalMachine
  2. Install target version Node.js by administrator.
  3. Attempt to run npm command, for example npm -v.
  4. Observe that npm fails because npm.ps1 is not digitally signed.
  5. Change the PowerShell execution policy to "Remote Signed", which is not "AllSigned". Set-ExecutionPolicy RemoteSigned -Scope LocalMachine
  6. Attempt to run npm command with the same Node.js version, for example npm -v.
  7. Observe that npm command now runs successfully.

How often does it reproduce? Is there a required condition?

Installed with "AllSigned" PowerShell policy and Node.js >= 22, this problem always reproduce.

What is the expected behavior? Why is that the expected behavior?

Node.js can run npm command with any version of Node.js, even if the PowerShell execution policy is "AllSigned".
For example this screenshot (v20)

Image

What do you see instead?

Node.js can not run npm command with Node.js >= 22 as below screenshot, if the PowerShell execution policy is "AllSigned".
The error Message is below.

npm : File C:\nvm4w\nodejs\npm.ps1 cannot be loaded. The file C:\nvm4w\nodejs\npm.ps1 is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170.
At line:1 char:1
+ npm -v
+ ~~~
    + CategoryInfo          : SecurityError: (:) [], PSSecurityException
    + FullyQualifiedErrorId : UnauthorizedAccess
Image

Additional information

Though many people think it may be a matter of npm, but in this issue in npm, it was said that to fix this problem need to be coordinated with the Node project .
But any open issue about this problem in Node.js is not exist, so I raise this issue to Node.js side.
This bug occurs with below version. I checked those by switching Node.js version using nvm-windows.
I'm in trouble because I develop with machine with "AllSigned" PowerShell policy by Group-Policy.

Node.js Vesion npm Version included by Node.js Can run with AllSigned
v24.9.0 v11.6.0 NG
v22.20.0 v10.9.3 NG
v22.9.0 v10.8.3 NG
v22.5.1 v10.8.2 NG
v22.0.0 v10.5.1 NG
v21.7.3 v10.5.0 OK
v20.19.5 v10.8.2 OK

Activity

  1. BharathPESU commented on Nov 4, 2025

    @BharathPESU
  2. BharathPESU commented on Nov 4, 2025

    @BharathPESU

    Hi — I’d like to take this one.

    Summary of the problem (reproduced):

    On Windows 10 x64 with PowerShell execution policy AllSigned, running bundled npm fails for Node ≥ 22 because npm.ps1 is not digitally signed:

    npm : File C:\nvm4w\nodejs\npm.ps1 cannot be loaded. The file ...\ is not digitally signed.

    Changing the policy to RemoteSigned makes npm work.

    I reproduced this on Node 22.20.0 and Node 24.9.0 (both fail), while Node 21.x and 20.x work as expected. The failure consistently reproduces when Node was installed while the system policy is AllSigned.

    Why this matters: many Windows users (corporate / GPO environments) enforce AllSigned, so Node should either ship a signed npm.ps1 or provide an installer/launch shim that avoids unsigned PowerShell scripts being blocked.

    Plan / next steps I will take:

    Reproduce and document the failure with a minimal reproducible setup (nvm-windows + Set-ExecutionPolicy AllSigned), and capture exact installer behavior.

    Inspect how npm/npm.cmd/npm.ps1 are packaged in Node ≥ 22 releases (installer/zip layout) and check whether npm.ps1 is present, signed, or marked/unblocked by the installer.

    Evaluate possible fixes:

    Ship a digitally signed npm.ps1 (coordination with release/signing process), or

    Change the installer to create an executable shim (or use npm.cmd/node -e launcher) that does not rely on an unsigned PowerShell script when AllSigned is in effect, or

    Add a documented installer step that marks the script as trusted during install (if safe/acceptable).

    Produce a PR or a detailed proposal for the maintainers with test results and suggested remediation(s).

    I’m happy to submit the PR and follow through with testing on affected Node versions. Could you please assign this issue to me?

  3. pronitsateli731 commented on Nov 5, 2025

    @pronitsateli731
    Author

    @BharathPESU
    I'm happy to your comment and I tried to assign, but I couldn't find how to assign. It seems I don't have permission to assign issue.

    Image
  4. BharathPESU commented on Nov 5, 2025

    @BharathPESU

    can you some more detail about this issue

  5. pronitsateli731 commented on Nov 6, 2025

    @pronitsateli731
    Author

    @BharathPESU
    Thanks for your follow-up!
    Just to clarify, my previous comment was only about the GitHub permission — I wanted to assign the issue to you, but it seems I don’t have permission to do that (since I’m not a collaborator on the repo).

    Regarding the issue itself, your summary is perfectly accurate. I don’t have anything to add at this point.

    Thanks again for taking this up!

  6. github-actions commented on Jun 5, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  7. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 5, 2026
  8. github-actions commented on Jul 6, 2026

    @github-actions
    Contributor

    This issue has been automatically closed after 30 days of inactivity following its stale status (no activity for a total of 240 days).
    If this is still relevant, feel free to reopen it or leave a comment with additional details so we can continue the discussion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions