The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

GitHub pulls pin on npm's auto-run scripts

GitHub will change npm's defaults so the install command no longer runs scripts automatically, disabling a feature commonly exploited by malicious packages such as the notorious Shai-Hulud worm. Maintainer Leo Balter said: "Install-time lifecycle scripts are the single largest code-execution surface in the npm ecosystem. Every npm install runs scripts from every transitive dependency, so a single compromised package anywhere in your tree can execute arbitrary code on a developer machine or CI (continuous integration) runner." In npm 12, due July, three security-focused defaults are changing. Scripts configured for preinstall, install, or postinstall will no longer run unless explicitly permitted via allow-scripts. The --allow-git flag, which pulls dependencies from remote URLs, will default to off, closing an attack path where a malicious .npmrc file could override the Git executable and achieve arbitrary code execution. Finally, allow-remote will default to none, blocking dependency downloads from remote URLs entirely. It will still be possible to allow scripts to run via an allowlist in the package.json configuration file. This will be pinned to the installed version of a package by default. These are breaking changes, and Balter recommended developers run the commands to allow scripts for every currently installed package in a project that requires them. "This gets you protected against new, unexpected scripts immediately," he said. The next step is to review these packages and deny scripts for those where they are not needed. Some packages require script approval to function, including native modules that compile on install, testing tools like Playwright and Puppeteer (which fetch binaries via postinstall), and Electron, which wraps the Chromium browser engine for cross-platform desktop applications. These features have been available since npm version 11.10.0, released in February, but as opt-in flags rather than defaults. That version also introduced min-release-age, which blocks installation of package version newer than a specified number of days, designed as a safeguard against newly published malicious packages. Best security practice for developers using npm 11.16, the current version, is to set these flags on in .npmrc or via environment variables, which will also prepare a project for the changes in version 12. One annoyance is that the existing flag ignore-scripts does not support an allowlist, other than via an additional tool. The ignore-scripts setting will override allow-scripts, so developers will need to remove it, if set to true, to enable approved scripts to run. The allowScripts setting exists in npm 11 but is advisory only. Will this fix npm security issues? Unfortunately not. "Now all the malware can move from the install script to the module itself where it will inevitably still be run," said one developer. Another common view is that developers should use pnpm, which already has safer defaults than npm, including a minimum release age. There is consensus, though, that these changes do improve npm security and are long overdue. The pull request for this change includes the remark that "npm is the only remaining major package manager that runs dependency install scripts by default. pnpm v10+, Yarn Berry, Bun, and Deno all block them." ®

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Als ik niet oppas met mijn digibete gekluns, belt binnenkort de politie aan

‘Resurrection’, over onsterfelijkheid en dromen, is een film die zich makkelijker laat waarderen dan liefhebben

Wanneer gaan de Europeanen de Straat van Hormuz weer bevaarbaar maken? De Verenigde Arabische Emiraten kunnen er niet op wachten

Europese landen moeten snel gaan helpen om de scheepvaart in de Straat van Hormuz weer mogelijk te maken. Dat zegt Mohammed Ibrahim Al Dhaheri, diplomaat van de Verenigde Arabische Emiraten. „Dit moet Teheran in toom houden.”

American capitalism has taken an apocalyptic turn

Millenarian thinking permeates business and markets.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Exciting transfer window will only exacerbate women’s football’s wealth gap

Alexis Putellas leads a host of stars expected to arrive in the WSL but smaller clubs will still struggle to keep pace

The whistle has blown on the 2025-26 season for the vast majority of women’s teams around the world, and attention now turns to the hullabaloo of the transfer window and another summer of rising wages, transfer fees and agents fees.

This summer’s activity is likely to see the gap between the haves and the have-nots widen further. Last summer there was an 83.6% increase in global spending on transfer fees in women’s football year-on-year, according to Fifa. This included headline-grabbing moves such as London City Lionesses’ £1.43m purchase of Grace Geyoro from Paris Saint-Germain, albeit London City have denied the figure is that high, and Arsenal’s landmark first £1m deal – the signing of Olivia Smith from Liverpool.

This is an extract from our free email about women’s football, Moving the Goalposts. To get the full edition, visit this page and follow the instructions. Moving the Goalposts will be sent out once a week, on Wednesdays, in the close season but will be back on Tuesdays and Thursdays from September.

Continue reading...

Sardinian beach bans umbrellas for people aged 10 to 65

Incredulous Italians ask if they should bring grandparents to beach to stay safe, after unpopular move in Villasimìus

Umbrellas have been banned on a beach in Sardinia for anyone between the ages of 10 and 65 in the latest flashpoint in Italy’s long-running beach disputes.

The measure was among several imposed by local authorities at Punta Molentis beach in Villasimìus, on Sardinia’s south-east coast, as part of an initiative to protect its pristine environment.

Continue reading...

‘Not just a singer’: Argentinians queue for miles to mourn biggest rockstar most of world has never heard of

Hundreds of thousands gather to remember Carlos ‘Indio’ Solari, who inspired cross-generational devotion, especially among working class

The line stretched for more than 7km (four miles). Mourners sang rock songs, waved banners, and carried speakers blasting music while smoke rose from makeshift barbecues and vendors sold T-shirts bearing the image of a bald man with sunglasses.

As evening fell, a drizzle set in, but the queue remained. At the end of the line in Avellaneda, outer Buenos Aires, stood a chapel containing the body of a rock star.

Continue reading...

Do not use our tragedy to fuel violence, family of Belfast attack victim say

Relatives of Stephen Ogilvie say unrest is unwelcome and that many migrants make valuable contribution to UK

The family of the victim of the Belfast knife attack have called for calm after riots erupted across the city.

Stephen Ogilvie is in hospital having lost his left eye in the attack, footage of which was shared widely on social media late on Monday evening and through the day on Tuesday.

Continue reading...

Formula 1 News

Formula 1® - The Official F1® Website

How to stream the Barcelona-Catalunya GP on F1 TV Premium

Here is all the information you need to follow the Barcelona-Catalunya Grand Prix weekend live on F1 TV.