npm 12 Released: Install Scripts Off by Default as Registry Moves to Explicit Trust
npm 12 introduces significant security-related changes, making certain installation behaviors opt-in. Notably, script allowances are now off by default, which requires explicit approval for running scripts, including implicit builds. The update also restricts non-registry sources and addresses community concerns about security risks from automatic script execution. By Daniel Curtis
GitHub-hosted package manager npm has released version 12, introducing security enhancements to the npm install process. This update deprecates granular access tokens that bypass two-factor authentication and modifies several install behaviors to require explicit opt-in. The default for allowScripts is now set to off, meaning that preinstall, install, and postinstall scripts will no longer run automatically.
This includes implicit node-gyp builds for packages with a binding.gyp file. Similarly, prepare scripts from git, file, and link dependencies are blocked by default. Developers must now explicitly allow scripts in their package.json file to run them. The changes also move non-registry sources to an explicit trust model, such as --allow-git now defaulting to none, and --allow-remote defaulting to none. These adjustments are part of GitHub's broader migration toward explicit trust in the npm registry.
Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.