When using an Alpine-based build image with npm 11 or npm 12, Bitbucket Pipelines injects the following environment variable:
NPM_CONFIG_USER=65534
This variable is not defined in our repository, workspace, deployment, pipeline configuration, or container image. Running the same image outside Bitbucket does not set it.
npm no longer supports user as a configuration option. With npm 11, every npm command reports:
npm warn Unknown env config "user". This will stop working in the next major version of npm.
With npm 12.0.2, it reports:
npm warn Unknown env config "user". This will error in a future major version of npm.
The commands currently still succeed, but the warning is noisy and suggests that the injected variable may cause failures in a future npm release.
Minimal reproduction:
image: node:24.18.1-alpine3.24
pipelines:
default:
- step:
script:
- env | grep -i '^npm_config_'
- npm --version
- npm config get userOutput includes:
NPM_CONFIG_USER=65534
npm warn Unknown env config "user"...
65534
The current workaround is:
unset NPM_CONFIG_USER
This must be applied in every pipeline step because each step starts a new container.
This appears related to behavior previously discussed here:
In the historical discussion, Atlassian recommended unset NPM_CONFIG_USER as a temporary workaround and identified an Alpine-specific issue. The behavior now appears to be present again, or was never completely removed.
Is NPM_CONFIG_USER=65534 still intentionally injected into Alpine build containers? If not, could it be removed for modern npm versions?