Skip to content

doc: update npm install steps - #484

Merged
kadler merged 6 commits into
mainfrom
doc-npm-approve-scripts
Sep 23, 2026
Merged

kadler merged 6 commits into
mainfrom
doc-npm-approve-scripts

Conversation

@abmusse

@abmusse abmusse commented Jul 2, 2026 •

Copy link
Copy Markdown
Member

With npm v12, npm install will no longer automatically run scripts from your package dependencies, but instead must be explicitly marked as allowed/trusted. This is to reduce the potential for malware and the effect of other recent supply chain attacks to be performed.

node-odbc uses node-pre-gyp to automatically install a pre-built node binding from the corresponding GitHub release or fall back to building it from source if a pre-built is not available. Starting with npm v12, the node-pre-gyp install script will no longer be run unless explicitly allowed using npm approve-scripts odbc.

Fixes #478

With npm v12. `npm install` will no longer automatically run scripts from your package dependencies, but instead must be explicitly marked as allowed/trusted. This is to reduce the potential for malware and the effect of other recent supply chain attacks to be performed.

node-odbc uses node-pre-gyp to automatically install a pre-built node binding from the corresponding GitHub release or fall back to building it from source if a pre-built is not available. Starting with npm v12, the node-pre-gyp install script will no longer be run unless explicitly allowed using `npm approve-scripts odbc`.

Fixes #478
@abmusse
abmusse requested a review from kadler July 2, 2026 21:49
@kadler

kadler commented Jul 6, 2026

Copy link
Copy Markdown
Member

I really think we need to add a section to the readme towards the top which has the text from the PR description and some kind of warning logo.

Existing users are not likely to look at the installation instructions. Also, the installation instructions as given do not explain what the user is approving.

Comment thread README.md Outdated
```

We use [node-pre-gyp](https://github.com/mapbox/node-pre-gyp) to build and install a prebuilt binary with the package.
For the prebuilt binary to get installed you need to approve the install script and re-trigger the install script.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't quite right.

For the prebuilt binary to get installed

This doesn't just affect the prebuilt binary, but even building from source if there's no prebuilt binary.

and re-trigger the install script.

This only needs to be done once. Maybe we should mention this. And say that once it's been approved and package.json updated, then they won't need to do anything else.

Comment thread README.md Outdated
@kadler
kadler merged commit b02e305 into main Sep 23, 2026
5 checks passed
@kadler
kadler deleted the doc-npm-approve-scripts branch September 23, 2026 20:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

doc: Update npm install instructions for npm >= 12

2 participants