//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
GitHub plans to disable npm install scripts by default, a big supply-chain hardening move. Fewer packages should get to run arbitrary code just because you typed npm install — expect some build workflows to need explicit opt-in. 📦 #OpenSource #Security #DevOps
8h
npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.
thehackernews.com
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
TECH Overload