GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks
ID: 2a71a382-9614-55f4-93ba-e351ffe3ffc8
STIX ID: report--2a71a382-9614-55f4-93ba-e351ffe3ffc8
Feed Name: cybersecurityNews.com
GitHub announced security changes in npm v12 (expected July 2026) that disable automatic execution of dependency installation scripts by default (preinstall, install, postinstall) and tighten controls on Git and remote package sources; developers must explicitly approve scripts using approve-scripts/deny-scripts and may need to adjust CI/CD workflows. The update aims to reduce software supply chain attack risks by introducing an opt-in trust model for script execution and blocking implicit behaviors like node-gyp rebuild unless permitted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
