logo

GitHub announces npm security changes to tackle supply-chain attacks

ID: 6eeea15b-f291-570f-ac6b-35eda0034756

STIX ID: report--6eeea15b-f291-570f-ac6b-35eda0034756

Feed Name: Bleeping Computer

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Bill Toulas

...
...

GitHub announced that npm v12 will disable automatic execution of dependency install scripts (preinstall/install/postinstall), block Git-based and remote URL dependencies by default, and require explicit approval for these actions to reduce supply-chain attack vectors; developers are advised to upgrade to npm 11.16.0 to preview warnings and identify workflows that will need explicit opt-in before moving to v12.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.