# GitHub Pulls Pin on Npm's Auto-Run Scripts

## npm v12 will require explicit approval for dependency scripts and Git or URL sources, closing code-execution paths abused in recent attacks.

- GitHub announced next month its package manager will introduce security-focused changes requiring explicit approval for scripts and remote sources previously trusted by default.
- "This gets you protected against new, unexpected scripts immediately," Maintainer Leo Balter said, noting install-time lifecycle scripts currently trigger automatically from every transitive dependency.
- Starting in version 12, the manager blocks automatic installation scripts, Git-based dependencies, and remote URL fetching unless explicitly permitted by developers.
- Developers should upgrade to npm 11.16.0 now to identify workflows that will break, as the version displays warnings for all actions requiring explicit approval.
- While Bun, Deno, and Yarn Berry already block these scripts, some developers worry malware will move to modules, though consensus remains these changes are long overdue.

### Coverage Details

Total News Sources: 12

Leaning Left: 0  
Leaning Right: 0  
Center: 2  
Last Updated: 14 hours ago

Bias Distribution: 100% Center

### Sources
- [GitHub announces npm security changes to tackle supply-chain attacks](https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/)  
- [GitHub pulls pin on npm's auto-run scripts](https://www.theregister.com/devops/2026/06/10/github-pulls-pin-on-npms-auto-run-scripts/5253453)  
- [The Era of Simply Running "Npm Install" to Execute Code Is Coming to an End](https://gigazine.net/news/20260611-npm-install-script/)

Heise broke the news in Germany 2 days ago on Wednesday, June 10, 2026.
