Finn Bayer

@finnbayer.de

he/him Frontend Dev from Germany Don't forget to love each other 🌈

npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...

npm install-time security and GAT bypass2fa deprecation - GitHub Changelog

npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…

github.blog

While I agree with this take it should still be a set value in every current config just to make sure that every person gets the benefit. Even if persons use a version of a package manager that does not set a default (pnpm before v11, current Npm versions etc). Goal: default in pm + set config value

Wes@notwes.bsky.social · 2mo ago

I will add a personal opinion: putting this config in every user repo is an asinine decision from a maintainability perspective. Secure defaults (which could include a delay until a package can be scanned before being available from the registry) is a much more scalable solution.

We just released the 4.14 branch! 🎊 Two important security changes: - `enableScripts` now defaults to `false` (can be overridden on a per-package basis) - A new `approvedGitRepositories` setting should be used to tell Yarn which git repos are safe to pack.

A lot has happened in the last two minor releases of the npm cli that is important to know for people using it: v11.9 : allow-git flag v11.10: min-release-age 🧵

Did my first talk regarding npm supply chain attacks at an internal developer conference last week. 🎉 My main talking point: Pay attention. It is so easy to mindlessly run an npm install without thinking about possible consequences. 🧵

White male person presenting. He is pointing and looking at a screen which can’t be seen