hacker-news · Crawled Jul 9, 2026

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

Read original article ↗

AI Summary

GitHub has released npm version 12, disabling install scripts by default to reduce supply chain risks. The update requires explicit user approval for lifecycle scripts, Git dependencies, and remote URL resolutions. Additionally, granular access tokens (GATs) that bypass 2FA are being restricted from performing sensitive account and package management actions, with full publishing capabilities removed in a future update. These changes aim to harden npm's security posture against automated attacks and token misuse.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.