Hacker News new | past | comments | ask | show | jobs | submit

Upcoming breaking changes for NPM v12

https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
I hope GitHub changes their vibecoded badges, what does RETIRED even signify in this context? Why does the preview have to be in ominous red?
loading story #48468308
loading story #48469284
this release fixes a vulnerability reported 10 years ago

https://www.kb.cert.org/vuls/id/319816

loading story #48468973
didn't know npm was owned by github.. well, that explains things...
loading story #48468559
loading story #48468144
loading story #48468504
loading story #48468917
loading story #48469000
loading story #48468862
They should have added a 1-day age limit by default, so security scanners have some time.
Looks good? But doesn't this just change the compromise window from first installation to first run?
loading story #48468572
loading story #48468535
loading story #48468271
loading story #48469227