NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

New Products

Summary

GitHub is changing npm 12 so dependency scripts will not run by default. The update targets a recent wave of supply chain attacks that abused automatic script execution during npm install. Developers will need to explicitly approve trusted scripts and may also need to allow git and remote URL dependencies. GitHub says the new behavior will help block malware delivery and reduce code execution risk across projects.

Classifications

industries
Fintech & Banking
applications
Data Management

AskAI Classifications

Labels
No AI classifications detected

Linked Companies

Semmle
$1M to $5M