NPM v12, estimated for July 2026, makes --allow-git and --allow-remote default to none, blocking Git and remote URL dependencies unless explicitly opted in. These changes are available as warnings in npm 11.16.0+. Developers should run npm approve-scripts to approve trusted scripts before upgrading.
Tap to vote and see what everyone thinks.