Skip to main content
See every side of every news story
Published loading...Updated

GitHub Pulls Pin on Npm's Auto-Run Scripts

npm v12 will require explicit approval for dependency scripts and Git or URL sources, closing code-execution paths abused in recent attacks.

  • GitHub announced next month its package manager will introduce security-focused changes requiring explicit approval for scripts and remote sources previously trusted by default.
  • "This gets you protected against new, unexpected scripts immediately," Maintainer Leo Balter said, noting install-time lifecycle scripts currently trigger automatically from every transitive dependency.
  • Starting in version 12, the manager blocks automatic installation scripts, Git-based dependencies, and remote URL fetching unless explicitly permitted by developers.
  • Developers should upgrade to npm 11.16.0 now to identify workflows that will break, as the version displays warnings for all actions requiring explicit approval.
  • While Bun, Deno, and Yarn Berry already block these scripts, some developers worry malware will move to modules, though consensus remains these changes are long overdue.
Insights by Ground AI
Podcasts & Opinions

12 Articles

A worm that replicates itself, thousands of secrets published in the open, cryptic wallets siphoned. npm v12 learns the lessons of the hecatombe: no more installation scripts will run without your consent.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Heise broke the news in Germany on Wednesday, June 10, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal