Wire · regulatory
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 10 July 2026 · Fusion42 review
npm 12 disables install scripts by default and requires explicit opt-in for dependency lifecycle scripts, Git dependencies, and remote URLs. GitHub also deprecates granular access tokens (GATs) that bypass two-factor authentication, blocking their use for sensitive account and package management actions.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.
◆ ◆ The Wire takeaway
If you ship Node.js code, your builds will break until you audit and allowlist your dependencies—and that's the point. This default-off model means your supply chain just got auditable, but you need to move fast: reviewers now see exactly which scripts run, and that visibility becomes a competitive advantage if your competitors stay blind.
◆ Coverage
1 source · 10 Jul 2026
◆ Related on Wire
◆ Topics