# A reminder about the turning off of npm install scripts

**URL:** <https://discourse.nodered.org/t/a-reminder-about-the-turning-off-of-npm-install-scripts/101308>\
**Category:** Developing Nodes\
**Created:** [18 June 2026 13:58 UTC](https://discourse.nodered.org/t/a-reminder-about-the-turning-off-of-npm-install-scripts/101308 "2026-06-18T13:58:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 June 2026 13:58 UTC](https://discourse.nodered.org/t/a-reminder-about-the-turning-off-of-npm-install-scripts/101308/1 "2026-06-18T13:58:43Z")

</div>

preinstall, install, and postinstall scripts will no longer run by default in the next major release of npm. We should be preparing for this now. The change is to prevent some really serious security issues that are being actively exploited right now.

So if you are a node author that uses one or more of these scripts, you should look for alternative approaches.

> Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available behind warnings in npm today on 11.16.0 or newer, so you can prepare before the upgrade. v12 is estimated to release in July 2026.

> **[Upcoming breaking changes for npm v12 - GitHub Changelog](https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/)**
>
> Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available behind warnings in npm today on 11.16.0 or newer, so you can…

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [18 June 2026 18:15 UTC](https://discourse.nodered.org/t/a-reminder-about-the-turning-off-of-npm-install-scripts/101308/2 "2026-06-18T18:15:15Z")

</div>

> <https://github.com/node-red/node-red/issues/5795>
>
> NPM v12 makes some breaking changes to its default behaviour for improved securi…ty.
> 
> https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
> 
> Specifically, it won't run npm scripts by default when installing modules. This is good for security, tricky for us.
> 
> I've examined the current state of the Node-RED library ecosystem to find there are 72 packages with install scripts. preinstall=14 install=9 postinstall=53. This only covers the top-level module - not the dependency trees. To disable scripts would risk breaking these nodes.
> 
> We have two choices.
> 
> \### Enable scripts by default
> 
> Essentially, maintain the existing behaviour for our users. This is the easy option; but that doesn't mean its the right option.
> 
> \### Update install workflow to include a script check
> 
> There is a good reason for disabling scripts by default. The npm cli will provide ways to approve scripts. We could update the install workflow to handle getting the user's consent before running any scripts. Not straight-forward to do. As far as I can tell, you have to run the \`npm install\` then check to see if there are any pending scripts. This will mean the files are on disk and can be loaded - node doesn't block the require/import if the scripts haven't run yet. Should NR refuse to start flows if there are pending scripts? Lots of lifecycle things to consider.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [17 August 2026 18:15 UTC](https://discourse.nodered.org/t/a-reminder-about-the-turning-off-of-npm-install-scripts/101308/3 "2026-08-17T18:15:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
