Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
July 2026, blocking install scripts, Git dependencies, and remote URL sources by default. Every team running npm install in ...
With npm v12, GitHub closes a central attack vector: installation scripts from dependencies will only run after explicit ...