npm v12 will disable dependency install scripts and block Git or remote URL dependencies by default in July 2026
EDITOR BRIEF
npm v12, expected in July 2026, will make security-focused breaking changes to npm install by requiring explicit opt-in for dependency lifecycle scripts, Git dependencies, and remote URL dependencies. Developers can preview warnings in npm 11.16.0+ and use approve-scripts or related allow flags to prepare projects before the upgrade.
INSIGHTS
The changes reflect a broader shift toward secure-by-default package management as supply-chain attacks increasingly abuse install-time code execution and non-registry dependencies. Teams with native modules, Git-based dependencies, or custom install workflows will need to audit and document trust decisions earlier in their build pipelines.
COMMENTS
Discussion
> geekhaus:~$ next read?
Next read recommendations

VentureBeat
Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities
metr.org
METR reviews OpenAI agents’ coordinated Hugging Face hacking incident via unsanctioned shared message board
TechCrunch