Skip to content

Framework: Update npm to v12 #82328

Description

@manzoorwanijk

What problem does this address?

npm 12 shipped on 8 July 2026 as a security release. Three things npm install does automatically today become opt-in: dependency lifecycle scripts (allowScripts), git dependencies (--allow-git), and remote URL dependencies (--allow-remote). See the announcement and RFC 54.

We normally pick up an npm major by moving to the Node.js version that bundles it. That path is closed here. The Node.js Release WG decided not to land npm 12 on Node.js 26, 24 or 22. Node.js 26 becomes Active LTS on 28 October 2026 still bundling npm 11, and under the new annual release schedule the next major, Node.js 27, is Current on 22 April 2027 and LTS that October. Waiting for a bundled npm 12 keeps us on npm 11 for another year with the supply chain protections switched off.

Meanwhile npm@latest already resolves to 12.0.2, so contributors installing the latest npm are on a major we have never tested against. Related: #72143.

What is your proposed solution?

Install npm 12 explicitly, decoupled from the bundled Node.js version. npm 12 requires Node.js ^22.22.2 || ^24.15.0 || >=26.0.0, so the 24.18 line we are moving to in #72973 already satisfies it.

Steps

  1. Land the Node.js 24 / npm 11 update first (Framework: Update Node.js to v24 LTS and npm to v11 #80395, tracked in Framework: Update Node.js version to v24 LTS #72973).
  2. Audit what the new defaults block (see below) and decide what we approve.
  3. Request that Systems install npm 12 on the wordpress.org build server. It will not arrive with a Node.js update, so it has to be installed explicitly, as Node.js itself was in 2023.
  4. Bump the repo pins. Since CI: Read the required npm version from a single source #82235, devEngines.packageManager.version in the root package.json is the single source of truth for the npm version CI and the release tooling install, so this is a one-line change plus engines.npm.
  5. Update wordpress-develop and the bundled default themes to match, with a Core ticket, coordinated so that both repositories move around the same time.
  6. Update the WordPress Branches and Node.js/npm Versions handbook page and our contributor docs.

What the new defaults hit on trunk

  • Ten dependency packages declare install scripts and will be blocked unless listed in allowScripts: @parcel/watcher, @swc/core, core-js, core-js-pure, esbuild, fs-ext, fsevents, leveldown, nx, unrs-resolver. Several fetch or build native binaries, and fs-ext and leveldown are node-gyp builds.
  • No git or remote URL dependencies, so --allow-git and --allow-remote can stay at their new defaults.
  • packages/icons generates src/library from a prepare script. Workspace packages are link dependencies and npm 12 blocks prepare for those, so this needs verifying before the bump.

Thoughts?

CC: @aduth @desrosj @johnbillion @tyxla @jsnajdr @Mamaduka @ciampo @lancewillett @adimoldovan

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions