Urgent.News

What's breaking now, across thousands of outlets.

Tech

Package Manager Trends

The trends in package manager usage over the past sixteen weeks have shown a recurring pattern of defensive features being implemented across multiple tools. These defensive features include release-age cooldowns, install-script blocking, and malware checks at install and publish time. Release-age cooldowns, such as Deno's min-release-age in its .npmrc handling, have been added to various tools, including Bundler, npm, Yarn, mise, Hex, Mamba, and Cargo.

Dependabot introduced a default three-day cooldown in August, while npm 12 and pnpm 12 now error on unrecognised config keys instead of skipping them. Install-script blocking has become the default in JavaScript tools, with npm 12 blocking lifecycle scripts by default and Bun 1.4 restricting auto-trust to packages fetched from the npm registry.

Malware checks have also been implemented in Composer 2.10, uv, and the npm registry, providing an additional layer of security during the installation and publishing process.

Brief written by urgent.news from Lobsters's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at nesbitt.io →

More in Tech

More from Thursday 10 September →