NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
Summary
GitHub is changing npm 12 so dependency scripts will not run by default. The update targets a recent wave of supply chain attacks that abused automatic script execution during npm install. Developers will need to explicitly approve trusted scripts and may also need to allow git and remote URL dependencies. GitHub says the new behavior will help block malware delivery and reduce code execution risk across projects.
Classifications
industries
Fintech & Banking
applications
Data Management
AskAI Classifications
Labels
No AI classifications detected
Linked Companies
Semmle
$1M to $5M