GitHub Pulls Pin on Npm's Auto-Run Scripts

npm v12 will require explicit approval for dependency scripts and Git or URL sources, closing code-execution paths abused in recent attacks.

  • GitHub announced next month its package manager will introduce security-focused changes requiring explicit approval for scripts and remote sources previously trusted by default.
  • "This gets you protected against new, unexpected scripts immediately," Maintainer Leo Balter said, noting install-time lifecycle scripts currently trigger automatically from every transitive dependency.
  • Starting in version 12, the manager blocks automatic installation scripts, Git-based dependencies, and remote URL fetching unless explicitly permitted by developers.
  • Developers should upgrade to npm 11.16.0 now to identify workflows that will break, as the version displays warnings for all actions requiring explicit approval.
  • While Bun, Deno, and Yarn Berry already block these scripts, some developers worry malware will move to modules, though consensus remains these changes are long overdue.

Coverage Details

Total News Sources: 12

Leaning Left: 0
Leaning Right: 0
Center: 2
Last Updated: 14 hours ago

Bias Distribution: 100% Center

Sources

Heise broke the news in Germany 2 days ago on Wednesday, June 10, 2026.