
npm v12 will block install scripts and Git dependencies by default
GitHub has detailed the breaking changes coming in npm v12: dependency install scripts, Git dependencies and remote URL dependencies will all be off by default. The release is expected in July 2026, and the warnings already appear in npm 11.16.0 and later.
What changes in npm v12
GitHub has published the list of breaking changes that will ship with npm v12, the next major version of the JavaScript package manager, expected in July 2026. The release turns several behaviours of npm install that happen automatically today into steps developers have to opt into explicitly. All of the changes are already available as warnings in npm 11.16.0 and newer, so projects can prepare before upgrading.
Install scripts become opt-in
The biggest change is that allowScripts defaults to off. After the upgrade, npm install will no longer execute preinstall, install or postinstall scripts from dependencies unless they are explicitly allowed in the project. That includes native node-gyp builds: a package that ships a binding.gyp file but no explicit install script is still blocked, because npm normally triggers an implicit node-gyp rebuild for it. prepare scripts from Git, file and link dependencies are blocked the same way.
To see what would be blocked, developers can run npm approve-scripts --allow-scripts-pending, then allow the packages they trust with npm approve-scripts and block the rest with npm deny-scripts. The resulting allowlist is written to package.json and should be committed to the repository.
Git and remote dependencies off by default
Two more flags change their defaults. --allow-git becomes none, so npm install will no longer resolve Git dependencies, direct or transitive, unless they are explicitly allowed. GitHub says this closes a code-execution path in which a Git dependency's .npmrc file could override the Git executable even when --ignore-scripts is used; the change was first announced on 18 February 2026 and is available in npm 11.10.0 and later.
--allow-remote also defaults to none: dependencies from remote URLs, such as HTTPS tarballs, are no longer resolved unless explicitly allowed. That flag is available in npm 11.15.0 and newer. The related --allow-file and --allow-directory flags keep their current defaults in v12.
How to prepare
GitHub's advice is to upgrade to npm 11.16.0 or later, run the usual install and review the warnings. Then use npm approve-scripts --allow-scripts-pending to list the packages that have scripts, approve the ones that are trusted and commit the updated package.json. After the upgrade only approved scripts keep running — anything left unapproved simply stops. Documentation for npm approve-scripts, npm deny-scripts and the allow-scripts configuration used by npx and global installs is available on the npm docs site, and discussion is taking place in GitHub Community.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.