Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

npm v12 delivers one of the biggest security improvements in years

Summary

npm v12 (July 2026) stops running dependency install scripts by default, requiring an allowlist—closing the postinstall vector exploited by Shai-Hulud and Nx, plus stricter git dependency rules.
Published
Collected

original ↗

Related coverage

back