hacker-news · Crawled Jul 9, 2026
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
Read original article ↗AI Summary
GitHub has released npm version 12, disabling install scripts by default to reduce supply chain risks. The update requires explicit user approval for lifecycle scripts, Git dependencies, and remote URL resolutions. Additionally, granular access tokens (GATs) that bypass 2FA are being restricted from performing sensitive account and package management actions, with full publishing capabilities removed in a future update. These changes aim to harden npm's security posture against automated attacks and token misuse.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.