GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
- Posted on June 11, 2026
- By The Hacker News
- 0 Views
- 1 min read
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
npm 12 disables install scripts by default, requiring explicit approval to reduce dependency-based code execution risks.