# Can't npm unpublish when a package has more than one versions

**URL:** <https://community.sonatype.com/t/cant-npm-unpublish-when-a-package-has-more-than-one-versions/8501>\
**Category:** Sonatype Nexus Repository\
**Tags:** nexus-repository\
**Created:** [April 10, 2022, 2:45pm UTC](https://community.sonatype.com/t/cant-npm-unpublish-when-a-package-has-more-than-one-versions/8501 "2022-04-10T14:45:06Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![wangqing](https://avatars.discourse-cdn.com/v4/letter/w/919ad9/32.png) [@wangqing](https://community.sonatype.com/u/wangqing)\
**Post date:** [April 10, 2022, 2:45pm UTC](https://community.sonatype.com/t/cant-npm-unpublish-when-a-package-has-more-than-one-versions/8501/1 "2022-04-10T14:45:06Z")

</div>

Nexus OSS 3.37.0-01, a hosted npm registry was setup.

When we unpublished a package with more than one version, an E500 error happened.

 ![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/2X/7/7f8d6c6046c36511e5fddc63ae76f57d2e19e050.png)

But if we --force unpublish the package or unpublish a package with only one version, everything goes fine.

The error was about metadata of the package:

```auto
java.lang.IllegalStateException: Package test-nexus lacks tarball version 0.1.1
	at com.google.common.base.Preconditions.checkState(Preconditions.java:826)

```

Actually the tarball of test-nexus@0.1.1 is already in the registry, and can be found in the NRM. The problem here maybe relate with the code below, which may not retrieve the metadata of package successfully.

```auto
// NpmHostedFacetImpl.updateDeprecationFlags
packageRoot.child(NpmMetadataUtils.VERSIONS)

```
