nodejs/node · error · Error
Package name must be specified either as an argument or in t
Error message
Package name must be specified either as an argument or in the package.json file
What it means
Thrown by `npm trust revoke` when neither a positional package name nor a resolvable package.json `name` is available. revoke needs the escaped name to DELETE `/-/package/<escapedName>/trust/<id>`. optionalPkgJson returns {} on any read failure so pkgName stays undefined.
Source
Thrown at deps/npm/lib/commands/trust/revoke.js:32
'[package] --id=<trust-id>',
]
static definitions = [
new Definition('id', {
default: null,
type: String,
description: 'ID of the trusted relationship to revoke',
required: true,
}),
globalDefinitions['dry-run'],
globalDefinitions.registry,
]
async exec (positionalArgs, flags) {
const dryRun = this.config.get('dry-run')
const pkgName = positionalArgs[0] || (await this.optionalPkgJson()).name
if (!pkgName) {
throw new Error('Package name must be specified either as an argument or in the package.json file')
}
const { id } = flags
if (!id) {
throw new Error('ID of the trusted relationship to revoke must be specified with the --id option')
}
this.dialogue`Attempting to revoke trusted configuration for package ${pkgName} with id ${id}`
if (dryRun) {
return
}
const spec = npa(pkgName)
const uri = `/-/package/${spec.escapedName}/trust/${encodeURIComponent(id)}`
await otplease(this.npm, this.npm.flatOptions, opts => npmFetch(uri, {
...opts,
method: 'DELETE',
}))
this.dialogue`Revoked trusted configuration for package ${pkgName} with id ${id}`
}
}View on GitHub (pinned to 1b2de5e052)
Solutions
- Pass the package name positionally: `npm trust revoke <pkg> --id <id>`.
- Run inside the package's own directory so package.json provides the name.
- Add/restore the `name` field in the local package.json.
Example fix
// before npm trust revoke --id abc123 // after npm trust revoke @my-scope/my-pkg --id abc123
Defensive patterns
Strategy: validation
Validate before calling
const pkgName = positionalArg || (await readPkgJsonSafe()).name
if (!pkgName) {
throw new Error('Provide the package name positionally or via package.json#name before revoking')
} Type guard
const hasUsableName = (positional, pkg) => Boolean(positional) || Boolean(pkg && pkg.name)
Try / catch
try {
await trustRevoke.exec([maybePkg], { id })
} catch (err) {
if (/Package name must be specified/i.test(err.message)) {
// supply positional package and retry
} else { throw err }
} Prevention
- Pass the package name positionally in revoke scripts.
- Confirm you are in the package's own directory when relying on package.json.
- Validate inputs in your automation before calling the command.
When it happens
Trigger: Running `npm trust revoke --id <id>` from a directory with no package.json or one lacking a name; forgetting the positional argument.
Common situations: Revoking a trust relationship for a package whose checkout you no longer have open; running from a CI working dir that only checked out a subpath; script automation that omits the positional.
Related errors
- Package name must be specified either as an argument or in t
- Package name must be specified either as an argument or in p
- ${providerEntity} must be specified with ${entityKey} option
- ${this.constructor.providerEntity} must be specified in the
- GitLab CI/CD pipeline file must be just a file not a path
AI-assisted analysis of nodejs/node@1b2de5e052 (2026-08-13).
Data as JSON: /api/errors/2b31e9a0c477f479.
Report an issue: GitHub.