generalnews.media
importance 4/5 Exclusive

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

npm version 12 now disables package install scripts by default, a major security change to prevent supply chain attacks. The move means packages cannot automatically run arbitrary code during installation unless explicitly enabled by developers. This reduces the risk of malicious scripts compromising systems, which has been a growing concern in the JavaScript ecosystem.

Security

Sources (1)

security
← Back to home