feat: block unreviewed install scripts by default (v12) - #9424
Merged
owlstronaut merged 1 commit intoJun 3, 2026
Merged
Conversation
bakkot
reviewed
May 28, 2026
|
It'd be great to address this: #9450 before/in the next major. with the allowlist feature, |
JamieMagee
force-pushed
the
jamiemagee/install-scripts-phase-2
branch
4 times, most recently
from
June 2, 2026 23:48
02a58af to
bb916b2
Compare
JamieMagee
marked this pull request as ready for review
June 2, 2026 23:52
bakkot
reviewed
Jun 3, 2026
allowScripts opt-in install-script policy
JamieMagee
force-pushed
the
jamiemagee/install-scripts-phase-2
branch
from
June 3, 2026 19:54
bb916b2 to
379b44a
Compare
JamieMagee
added a commit
to JamieMagee/cli-1
that referenced
this pull request
Jun 3, 2026
Behavior-neutral additive tooling split out of npm#9424 so it can land on v11 without the v12 default-deny flip: - arborist: add collectUnreviewedScripts() + strictAllowScriptsError (ESTRICTALLOWSCRIPTS) helpers in unreviewed-scripts.js - arborist: isScriptAllowed() returns null for bundled deps; propagate inBundle through isolated reifier / isolated-classes - libnpmexec: opt-in strict-allow-scripts preflight (only under --strict-allow-scripts); no default behavior change - cli: rewrite check-allow-scripts as a wrapper over collectUnreviewedScripts; exclude bundled deps from rebuild/runAll - tests for all of the above No default install-script behavior changes; the default-deny gate stays in npm#9424 for v12.
owlstronaut
pushed a commit
that referenced
this pull request
Jun 3, 2026
Pulls the non-behavioral pieces out of #9424 so they can land on v11: the `collectUnreviewedScripts`/`strictAllowScriptsError` helpers, the `inBundle` fixes, and an opt-in libnpmexec preflight. Nothing changes by default here, install scripts still run. The default-deny flip stays in #9424 for v12. ## References #9424
Phase 2 of the RFC npm#868 install-script policy: flip the default so unreviewed lifecycle scripts are blocked unless covered by allowScripts. Stacked on the behavior-neutral tooling PR; this commit carries ONLY the v12-only default flip: - arborist: gate preinstall/install/postinstall/prepare in rebuild on the allowScripts policy (default-deny) - user-facing "blocked because not covered by allowScripts" wording in rebuild/reify-output/allow-scripts-cmd - config definition docs + approve/deny command docs + snapshots - flip tests
JamieMagee
force-pushed
the
jamiemagee/install-scripts-phase-2
branch
from
June 3, 2026 21:06
379b44a to
7124eda
Compare
owlstronaut
approved these changes
Jun 3, 2026
3 tasks done
This was referenced Jul 31, 2026
This was referenced Aug 9, 2026
AceP2317
added a commit
to AceP2317/ian-pdf-pro
that referenced
this pull request
Oct 2, 2026
…12 blocks them npm 11 runs a dependency's install script that no allowScripts entry in package.json covers, and only warns. npm 12 (released 2026-07-08, npm's latest tag) blocks it instead (npm/cli#9424). This writes approvals for exactly the scripts that run now, pinned to the locked versions the way npm approve-scripts pins them, so installs behave the same on npm 11 and 12. Where a fast guard tier exists, a-package-install-script-has-no-decision-written refuses a commit whose lock installs a script with no decision. Its logic lives once, in ~/.claude/install-script-decisions.mjs, which reads package-lock.json. Rolled out to every repo on this PC with install scripts on the operator's pick, 2026-10-02 (ian-provencher D88). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RpHHjRKJDKy8EVWh14JYG2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Flips the default so lifecycle scripts from packages not covered by
allowScriptsare blocked instead of run. The shared helpers andinBundlefixes this depends on are split into #9480, so this PR is now just the default change and the wording, docs, and snapshot updates that come with it. Targetslatestonly since it needs a major.