Skip to content

Security: Opt in to the npm v12 supply-chain defaults - #82689

Closed
manzoorwanijk wants to merge 2 commits into
trunkfrom
update/npm-supply-chain-defaults
Closed

manzoorwanijk wants to merge 2 commits into
trunkfrom
update/npm-supply-chain-defaults

Conversation

@manzoorwanijk

@manzoorwanijk manzoorwanijk commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

What?

Closes #74877. Follow up to #82370. Opts in to the npm supply chain protections that become the default in npm v12.

Partial and temporary: #82328 tracks installing npm 12, after which these become defaults.

Why?

Revives #79614, reverted in #79667.

How?

.npmrc refuses git references, tarball URLs and local tarballs, and limits directory dependencies to those the root or a workspace declares.

allowScripts denies all ten dependencies that ship an install script, and strict-allow-scripts fails the install on anything absent from that list. #74877 proposed ignore-scripts, which would also disable our own scripts; this blocks dependencies only.

Testing Instructions

  1. Remove every node_modules, then npm ci. package-lock.json should be unchanged.
  2. npm run build, npm run typecheck and npm run lint:js should pass.
  3. Confirm each gate fires (the third edits package.json):
npm install --dry-run --no-save github:sindresorhus/is-odd
npm install --dry-run --no-save https://registry.npmjs.org/is-odd/-/is-odd-3.0.1.tgz
npm pkg delete allowScripts.esbuild && npm install --dry-run
git checkout package.json
  1. In a scratch directory run npm init -y && npm link, then from the repo:
npm install --dry-run --no-save <scratch directory>
npm link --dry-run <scratch package name>

Testing Instructions for Keyboard

N/A, no user interface change.

Use of AI Tools

Claude Code researched the npm settings and verified them against clean installs. I reviewed all changes.

🤖 Generated with Claude Code

Now that CI and contributors are on Node 24 with npm v11 (5715a61), the
repository can adopt the hardening that npm v12 turns on by default.

Dependencies must resolve from the registry: git references, tarball URLs and
local tarball files are refused outright, since nothing in the tree uses them.
Directory dependencies stay allowed for the root and workspace package.json
files, which the 1121 `file:` workspace links need, but a transitive dependency
can no longer pull one in.

Install scripts are denied by default. Every dependency that ships one is
listed as `false` in the allowScripts policy, and strict-allow-scripts makes
anything missing from that list a failed install rather than a warning. Nothing
here needs its install script: build, typecheck, lint and unit tests all pass
with them skipped.

Both policies surface as an install failure rather than a warning, so the
contributor workflow for each is documented alongside them.

This revives #79614, which had to be reverted in #79667 because CI still ran an
npm that predated these features.
@manzoorwanijk manzoorwanijk added the [Type] Security Related to security concerns or efforts label Sep 9, 2026
@manzoorwanijk manzoorwanijk self-assigned this Sep 9, 2026
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review September 9, 2026 16:45
@github-actions

github-actions Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

🤖 PR meta 🤖

📦 Bundle size

Size Change: 0 B

Total Size: 8.07 MB

e4e1b58 Run

⚡ Performance

Show the results

Client side metrics exclude the server response time.

front-end-block-theme

Metric acdf908 trunk % Change
timeToFirstByte 55.55 ms +7.2% -2.43% 56.65 ms +14.56% -4.5% -1.94%
largestContentfulPaint 88 ms +6.82% -0% 98 ms +10.2% -8.16% -10.2%
lcpMinusTtfb 33.55 ms +3.58% -3.28% 37.5 ms +16.93% -8.13% -10.53%
wpBeforeTemplate 27.45 ms +7.76% -0.84% 28.49 ms +20.67% -3.69% -3.65%
wpTemplate 23.77 ms +3.79% -2.02% 23.98 ms +7.55% -3.84% -0.88%
wpTotal 51.94 ms +7.57% -2.64% 52.84 ms +15.2% -4.54% -1.7%
wpMemoryUsage 7.53 MB +0% -0% 7.48 MB +0% -0% 0.61%
wpDbQueries 17 +0% -0% 17 +0% -0% 0%

front-end-classic-theme

Metric acdf908 trunk % Change
timeToFirstByte 43.7 ms +8.35% -1.72% 42.1 ms +5.7% -0.48% 3.8%
largestContentfulPaint 100 ms +2% -4% 96 ms +4.17% -0% 4.17%
lcpMinusTtfb 55.6 ms +1.53% -3.42% 54 ms +0.65% -1.2% 2.96%
wpBeforeTemplate 25.56 ms +9.04% -0.74% 25.33 ms +2.21% -1.03% 0.91%
wpTemplate 14.65 ms +3.82% -3.69% 14.11 ms +1.84% -2.27% 3.83%
wpTotal 40.61 ms +8.84% -1.97% 39.21 ms +5.94% -0.64% 3.57%
wpMemoryUsage 5.52 MB +0% -0% 5.47 MB +0% -0% 0.85%
wpDbQueries 14 +0% -0% 14 +0% -0% 0%

media-processing

Metric acdf908 trunk % Change
mediaProcessingJpeg 396.46 ms +0.21% -0.15% 398.69 ms +1.38% -0.67% -0.56%
mediaProcessingAvif 6063.17 ms +0.1% -0.21% 6023 ms +0.34% -0.11% 0.67%
mediaProcessingJpegToAvif 4169.5 ms +0.01% -0.15% 4162.63 ms +0.09% -0.28% 0.17%

media-upload

Metric acdf908 trunk % Change
jpegUploadProcessing 1447.38 ms +34.21% -2.3% 1423.21 ms +0.31% -0.53% 1.7%
pngUploadProcessing 217.26 ms +6.03% -5.56% 211.42 ms +2.12% -7.4% 2.76%
largeJpegUploadProcessing 1414.96 ms +0.93% -1.11% 1425.63 ms +0.33% -0.79% -0.75%
multipleImageUploadProcessing 1592.61 ms +9.95% -1.44% 1579.14 ms +0.79% -1.39% 0.85%

post-editor

Metric acdf908 trunk % Change
serverResponse 546.2 ms +2.04% -5.4% 494.84 ms +8.14% -1.3% 10.38%
firstPaint 230.41 ms +18.57% -22.92% 226.16 ms +40.85% -6.61% 1.88%
domContentLoaded 1308.83 ms +0.75% -1.23% 1312.41 ms +2.03% -1.76% -0.27%
loaded 1310.11 ms +0.76% -1.22% 1313.7 ms +2.02% -1.76% -0.27%
firstContentfulPaint 438.52 ms +4.6% -2.42% 446.28 ms +6.59% -4.85% -1.74%
firstBlock 3616.73 ms +0.38% -1.02% 3662.71 ms +0.22% -1.41% -1.26%
type 15.9 ms +2.89% -4.15% 14.85 ms +6.06% -2.69% 7.07%
typeWithoutInspector 14.68 ms +2.11% -5.99% 14.63 ms +3.62% -2.19% 0.34%
typeWithTopToolbar 18.31 ms +13.93% -7.81% 19.61 ms +2.5% -2.7% -6.63%
typeContainer 9.12 ms +11.95% -10.42% 9.51 ms +8.83% -5.26% -4.1%
focus 78.39 ms +15.49% -4.09% 84.27 ms +11.59% -4.02% -6.98%
firstFocus 179.52 ms +0% -0% 181.59 ms +0% -0% -1.14%
selectAll 589.55 ms +3.84% -0.1% 602.66 ms +2.67% -0.22% -2.18%
listViewOpen 68.39 ms +18.23% -1.78% 72.71 ms +11.43% -8.46% -5.94%
inserterOpen 23.1 ms +3.03% -7.49% 23.03 ms +6.69% -7.47% 0.3%
inserterHover 3.97 ms +15.87% -6.55% 3.6 ms +12.5% -2.5% 10.28%
inserterSearch 8.35 ms +15.09% -5.51% 8.07 ms +7.06% -2.35% 3.47%
loadPatterns 619.37 ms +6.24% -1.48% 651.42 ms +4.68% -2.92% -4.92%
wpTotal 536.27 ms +1.99% -5.38% 484.94 ms +8.23% -1.39% 10.58%
wpMemoryUsage 13.06 MB +0% -0% 13.02 MB +0% -0% 0.37%
wpDbQueries 54 +0% -1.85% 53 +1.89% -0% 1.89%

site-editor

Metric acdf908 trunk % Change
serverResponse 506.68 ms +4.57% -3.05% 522.05 ms +1.69% -4.51% -2.94%
firstPaint 296.04 ms +12.4% -21.2% 243.31 ms +13.21% -6.16% 21.67%
domContentLoaded 1428.83 ms +0.89% -0.87% 1404.51 ms +1.35% -0.26% 1.73%
loaded 1430.14 ms +0.88% -0.86% 1405.92 ms +1.34% -0.27% 1.72%
firstContentfulPaint 458.62 ms +2.13% -3.84% 442.15 ms +1.92% -2.68% 3.72%
firstBlock 4605.78 ms +1.99% -1.13% 4548.67 ms +0.33% -0.61% 1.26%
type 16.73 ms +6.04% -11.06% 15.72 ms +8.14% -12.66% 6.42%
navigate 101.15 ms +5.66% -4.66% 110.83 ms +22.36% -7.91% -8.73%
loadPatterns 1504.44 ms +3.57% -9.46% 1553.4 ms +4.55% -4.55% -3.15%
loadPages 1081.45 ms +0.78% -0.87% 1074.72 ms +1.5% -1.28% 0.63%
wpTotal 496.71 ms +4.68% -2.98% 512.23 ms +1.72% -4.58% -3.03%
wpMemoryUsage 12.07 MB +0% -0% 12.03 MB +0% -0% 0.39%
wpDbQueries 43 +2.33% -0% 43 +2.33% -0% 0%

e4e1b58 Run

🏁 Flaky tests

Show the failures

Some tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information.

As a site builder, I want to insert a core navigation overlay pattern with CTA and see it on the frontend (Site Editor v2) in /test/e2e/specs/site-editor/navigation-overlay-template-part.spec.js, passed after 1 failed attempt.
Error: expect(locator).toBeVisible() failed

Locator:  getByRole('option', { name: /Overlay with site info and CTA/i })
Expected: visible
Received: hidden
Timeout:  5000ms

Call log:
  - Expect "toBeVisible" getByRole('option', { name: /Overlay with site info and CTA/i }) with timeout 5000ms
  - waiting for getByRole('option', { name: /Overlay with site info and CTA/i })
    14 × locator resolved to <div role="option" tabindex="-1" data-base-ui-tooltip-trigger="" aria-label="Overlay with site info and CTA" class="block-editor-block-patterns-list__item" id="core/navigation-overlay-centered-with-extras" aria-describedby="block-editor-block-patterns-list__item-description-4">…</div>
       - unexpected value "hidden"

    at /home/runner/work/gutenberg/gutenberg/test/e2e/specs/site-editor/navigation-overlay-template-part.spec.js:227:31

e4e1b58 Run

@github-actions

github-actions Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: manzoorwanijk <manzoorwanijk@git.wordpress.org>
Co-authored-by: tyxla <tyxla@git.wordpress.org>
Co-authored-by: ciampo <mciampini@git.wordpress.org>
Co-authored-by: SirLouen <sirlouen@git.wordpress.org>
Co-authored-by: aduth <aduth@git.wordpress.org>
Co-authored-by: johnbillion <johnbillion@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@manzoorwanijk manzoorwanijk changed the title Framework: Opt in to the npm v12 supply-chain defaults Security: Opt in to the npm v12 supply-chain defaults Sep 9, 2026
Comment thread .npmrc
strict-allow-scripts = true
# only allow dependencies resolved from the registry
allow-git = none
allow-remote = none

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Won't this break npm ci for people who use a registry mirror (Artifactory, Nexus, a company proxy)? On npm 11, npm compares the tarball host from the lockfile with the registry host, and it does not apply replace-registry-host first. The lockfile always points to registry.npmjs.org, so those installs fail with EALLOWREMOTE and there is no way around it.

npm 12 fixes the comparison. Maybe we should land this after #82328?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It won't if you use the latest v11 (>=11.18). I fixed that bug in npm in npm/cli#9550

Comment thread package.json
"@swc/core": false,
"core-js": false,
"core-js-pure": false,
"esbuild": false,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On npm 11, denying an install script also skips bin linking, so node_modules/.bin/esbuild and node_modules/.bin/nx won't be created.

Our builds are fine because we import esbuild as a JS API, but npm exec --no -- esbuild stops working, and AGENTS.md tells contributors to use exactly that.

I believe that is also fixed in npm 12.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is also fixed in the latest version via npm/cli#9686

Install scripts are denied by default: every dependency that ships one is listed in `allowScripts` in the root `package.json`, and anything missing from that list fails the install with `ESTRICTALLOWSCRIPTS`. When that happens, read the script, then record the decision and commit the `package.json` change:

```bash
npm install-scripts deny <pkg> # the package works without its install script

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

npm install-scripts only exists in npm 12. On npm 11 it fails with Unknown command. npm 11 uses npm approve-scripts and npm deny-scripts instead. Maybe we should mention both, or say that this needs npm 12?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's updated in npm >= 11.18 after npm/cli#9629

Comment thread .github/CODEOWNERS Outdated
@manzoorwanijk

Copy link
Copy Markdown
Member Author

Do you all think that this should be done via #82328 - npm 12 upgrade instead?

@tyxla

tyxla commented Sep 10, 2026

Copy link
Copy Markdown
Member

Do you all think that this should be done via #82328 - npm 12 upgrade instead?

I wouldn't be opposed, but I honestly missed the fact that all of these were fixed in v11. It really depends on when v12 lands - if it takes a while, maybe it's worth doing these now while we're on v11.

@ciampo

ciampo commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

We could move gradually and merge this PR, and later update to npm 12?

@manzoorwanijk

Copy link
Copy Markdown
Member Author

My only concern is that the project's required minimum npm version has bugs, as @tyxla reported above. Should we expect the contributors to have the latest npm version regardless of what is required?

@ciampo

ciampo commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Mhh, that's a good counterpoint. Realistically, can we "afford" to wait longer and switch to npm 12 directly? If so, then maybe that's a better choice

@manzoorwanijk

Copy link
Copy Markdown
Member Author

Yes, I think it is better to push for #82328 to have npm v12 available ASAP.

manzoorwanijk added a commit that referenced this pull request Sep 10, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

Closes #82328. Supersedes #82689.
@manzoorwanijk

Copy link
Copy Markdown
Member Author

Closing in favor of #82732

@manzoorwanijk
manzoorwanijk deleted the update/npm-supply-chain-defaults branch September 11, 2026 11:59
manzoorwanijk added a commit that referenced this pull request Sep 14, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes. Create Block opts out
of the setup-node npm cache, which calls `npm config get cache` under the
bundled npm and fails the devEngines check.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 14, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 14, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 15, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 16, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 17, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 17, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 18, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 18, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 18, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 22, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 25, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 25, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 29, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Sep 29, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 1, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 1, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 2, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 2, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts.

npm v12 keys `pack --json` output by package name rather than returning
an array, so the two pack helpers read both shapes.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 2, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts, all
denied: nothing compiles on install.

npm 12 does not exempt workspace lifecycle scripts from allowScripts
under install-strategy=linked, so @wordpress/icons needs an entry of its
own to keep generating src/library on install. See
npm/cli#9982.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 2, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts, all
denied: nothing compiles on install.

npm 12 does not exempt workspace lifecycle scripts from allowScripts
under install-strategy=linked, so @wordpress/icons needs an entry of its
own to keep generating src/library on install. See
npm/cli#9982.

Closes #82328. Supersedes #82689.
manzoorwanijk added a commit that referenced this pull request Oct 2, 2026
Bump engines.npm and devEngines.packageManager to npm v12 and opt in to
the supply chain policy the new major requires. Install scripts are now
opt-in, so record every dependency that ships one in allowScripts, all
denied: nothing compiles on install.

npm 12 does not exempt workspace lifecycle scripts from allowScripts
under install-strategy=linked, so @wordpress/icons needs an entry of its
own to keep generating src/library on install. See
npm/cli#9982.

Closes #82328. Supersedes #82689.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

[Type] Security Related to security concerns or efforts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement ignore-scripts to harden npm usage

3 participants