npm 12’s New Security Defaults Won’t Save You. Here’s Why.
npm 12 makes install scripts, Git dependencies, and remote URLs opt-in by default. Security win, right? Not quite. The top comment on the changelog exposes the uncomfortable truth: developers will simply re-enable everything because the ecosystem has no safe alternatives. Defaults don’t save you when the culture is addicted to the practices they restrict. The real security feature isn’t the setting β it’s the pause before you override it.