GitHub Pulls Pin on Npm's Auto-Run Scripts
npm v12 will require explicit approval for dependency scripts and Git or URL sources, closing code-execution paths abused in recent attacks.
- GitHub announced next month its package manager will introduce security-focused changes requiring explicit approval for scripts and remote sources previously trusted by default.
- "This gets you protected against new, unexpected scripts immediately," Maintainer Leo Balter said, noting install-time lifecycle scripts currently trigger automatically from every transitive dependency.
- Starting in version 12, the manager blocks automatic installation scripts, Git-based dependencies, and remote URL fetching unless explicitly permitted by developers.
- Developers should upgrade to npm 11.16.0 now to identify workflows that will break, as the version displays warnings for all actions requiring explicit approval.
- While Bun, Deno, and Yarn Berry already block these scripts, some developers worry malware will move to modules, though consensus remains these changes are long overdue.
Coverage Details
Total News Sources: 12
Leaning Left: 0
Leaning Right: 0
Center: 2
Last Updated: 14 hours ago
Bias Distribution: 100% Center
Sources
- GitHub announces npm security changes to tackle supply-chain attacks
- GitHub pulls pin on npm's auto-run scripts
- The Era of Simply Running "Npm Install" to Execute Code Is Coming to an End
Heise broke the news in Germany 2 days ago on Wednesday, June 10, 2026.