You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
npm 12 shipped on 8 July 2026 as a security release. Three things npm install does automatically today become opt-in: dependency lifecycle scripts (allowScripts), git dependencies (--allow-git), and remote URL dependencies (--allow-remote). See the announcement and RFC 54.
We normally pick up an npm major by moving to the Node.js version that bundles it. That path is closed here. The Node.js Release WG decided not to land npm 12 on Node.js 26, 24 or 22. Node.js 26 becomes Active LTS on 28 October 2026 still bundling npm 11, and under the new annual release schedule the next major, Node.js 27, is Current on 22 April 2027 and LTS that October. Waiting for a bundled npm 12 keeps us on npm 11 for another year with the supply chain protections switched off.
Meanwhile npm@latest already resolves to 12.0.2, so contributors installing the latest npm are on a major we have never tested against. Related: #72143.
What is your proposed solution?
Install npm 12 explicitly, decoupled from the bundled Node.js version. npm 12 requires Node.js ^22.22.2 || ^24.15.0 || >=26.0.0, so the 24.18 line we are moving to in #72973 already satisfies it.
Audit what the new defaults block (see below) and decide what we approve.
Request that Systems install npm 12 on the wordpress.org build server. It will not arrive with a Node.js update, so it has to be installed explicitly, as Node.js itself was in 2023.
Bump the repo pins. Since CI: Read the required npm version from a single source #82235, devEngines.packageManager.version in the root package.json is the single source of truth for the npm version CI and the release tooling install, so this is a one-line change plus engines.npm.
Update wordpress-develop and the bundled default themes to match, with a Core ticket, coordinated so that both repositories move around the same time.
Ten dependency packages declare install scripts and will be blocked unless listed in allowScripts: @parcel/watcher, @swc/core, core-js, core-js-pure, esbuild, fs-ext, fsevents, leveldown, nx, unrs-resolver. Several fetch or build native binaries, and fs-ext and leveldown are node-gyp builds.
No git or remote URL dependencies, so --allow-git and --allow-remote can stay at their new defaults.
packages/icons generates src/library from a prepare script. Workspace packages are link dependencies and npm 12 blocks prepare for those, so this needs verifying before the bump.
What problem does this address?
npm 12 shipped on 8 July 2026 as a security release. Three things
npm installdoes automatically today become opt-in: dependency lifecycle scripts (allowScripts), git dependencies (--allow-git), and remote URL dependencies (--allow-remote). See the announcement and RFC 54.We normally pick up an npm major by moving to the Node.js version that bundles it. That path is closed here. The Node.js Release WG decided not to land npm 12 on Node.js 26, 24 or 22. Node.js 26 becomes Active LTS on 28 October 2026 still bundling npm 11, and under the new annual release schedule the next major, Node.js 27, is Current on 22 April 2027 and LTS that October. Waiting for a bundled npm 12 keeps us on npm 11 for another year with the supply chain protections switched off.
Meanwhile
npm@latestalready resolves to 12.0.2, so contributors installing the latest npm are on a major we have never tested against. Related: #72143.What is your proposed solution?
Install npm 12 explicitly, decoupled from the bundled Node.js version. npm 12 requires Node.js
^22.22.2 || ^24.15.0 || >=26.0.0, so the 24.18 line we are moving to in #72973 already satisfies it.Steps
devEngines.packageManager.versionin the rootpackage.jsonis the single source of truth for the npm version CI and the release tooling install, so this is a one-line change plusengines.npm.What the new defaults hit on
trunkallowScripts:@parcel/watcher,@swc/core,core-js,core-js-pure,esbuild,fs-ext,fsevents,leveldown,nx,unrs-resolver. Several fetch or build native binaries, andfs-extandleveldownarenode-gypbuilds.--allow-gitand--allow-remotecan stay at their new defaults.packages/iconsgeneratessrc/libraryfrom apreparescript. Workspace packages are link dependencies and npm 12 blockspreparefor those, so this needs verifying before the bump.Thoughts?
CC: @aduth @desrosj @johnbillion @tyxla @jsnajdr @Mamaduka @ciampo @lancewillett @adimoldovan