logo

GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks

ID: 2a71a382-9614-55f4-93ba-e351ffe3ffc8

STIX ID: report--2a71a382-9614-55f4-93ba-e351ffe3ffc8

Feed Name: cybersecurityNews.com

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Abinaya

...
...

GitHub announced security changes in npm v12 (expected July 2026) that disable automatic execution of dependency installation scripts by default (preinstall, install, postinstall) and tighten controls on Git and remote package sources; developers must explicitly approve scripts using approve-scripts/deny-scripts and may need to adjust CI/CD workflows. The update aims to reduce software supply chain attack risks by introducing an opt-in trust model for script execution and blocking implicit behaviors like node-gyp rebuild unless permitted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.