GitHub, the heart of the software world, has drawn its sword against npm attacks, which have become a nightmare for developers. With the npm 12 version to be released next month, scripts that are activated during installation will no longer be run by default.