npm

npm 12 Gives You Control Over Installation Scripts by Default

npm 12 puts security first by flipping a long-standing default: install scripts now run only with explicit approval.

3 min readInfoQ
npm 12 Gives You Control Over Installation Scripts by Default

The quiet shift in npm 12 is not about a new feature you will brag about at a meetup. It is about the registry finally admitting that trust must be earned, not assumed. By making install scripts opt-in and restricting non-registry sources, the team has drawn a line that many of us have been asking for since the first time a dependency chain ran something we never read. This is not a rebuke of the developers who use npm daily. It is a recalibration of what a package manager should protect: the time and security of the people who run `npm install` on a Friday afternoon without a second thought.

We have seen what happens when trust is misplaced in the software supply chain. Just recently, AI agents shared user images, exposing how quickly automated systems can leak what they were never meant to touch. And the North Korean hackers linked to $351M Bitget crypto theft remind us that the threat is not abstract; it is a business model for organized crime. In that context, npm's move to make script execution explicit feels less like a convenience trade-off and more like a necessary patch to a systemic hole. We are not talking about slowing down innovation. We are talking about making sure the innovation you run is actually what you think it is.

For the working developer, this means a small adjustment in daily habits that pays off in the long run. When you install a package and see a prompt asking for permission to run scripts, that is not an annoyance. That is the system asking you to make a judgment call. It is the difference between blindly accepting a binary and knowing what it does. The restriction on non-registry sources is equally important, because it closes the door on typosquatting and private registries that do not follow the same security baseline. We would tell anyone who asks: treat this as a feature, not a hurdle. If a package cannot explain why it needs to run code during installation, that is a strong signal it should not be running anything at all.

The broader lesson here is about ownership. As Anthropic Founders aim for majority voting control ahead of IPO, we see a parallel in how platforms and tools are governed. Whether it is a company trying to secure its own decision-making or a package manager deciding who gets to execute code, the theme is the same: explicit control beats implicit permission. npm 12 is not the end of the conversation, but it is a strong opening statement. The detail to watch is how the community responds to the added friction. If adoption stays steady and security reports drop, other ecosystems will follow. If not, we will have learned that convenience was the only thing standing between us and a very bad day.

From InfoQ

npm 12 introduces significant security-related changes, making certain installation behaviors opt-in. Notably, script allowances are now off by default, which requires explicit approval for running scripts, including implicit builds. The update also restricts non-registry sources and addresses community concerns about security risks from automatic script execution.

Read the original at InfoQ