User tests: Successful: Unsuccessful:
Pull Request resolves # .
With npm 12 you now need to explicitly allow scripts see https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
if you are on npm 11.6 and higher and run npm i you will see information at the end that you need to allow certain scripts.
npm warn install-scripts 5 packages had install scripts blocked because they are not covered by allowScripts:
npm warn install-scripts core-js@3.45.1 (postinstall: node -e "try{require('./postinstall')}catch(e){}")
npm warn install-scripts cypress@15.18.0 (postinstall: node dist/index.js --exec install)
npm warn install-scripts esbuild@0.25.10 (postinstall: node install.js)
npm warn install-scripts cypress@13.17.0 (postinstall: node index.js --exec install)
npm warn install-scripts vue-demi@0.13.11 (postinstall: node ./scripts/postinstall.js)
npm warn install-scripts
npm warn install-scripts Run `npm install-scripts ls` to review, or `npm install-scripts approve <pkg>` to allow.
no warnings
Please select:
Documentation link for guide.joomla.org:
No documentation changes for guide.joomla.org needed
Pull Request link for manual.joomla.org:
No documentation changes for manual.joomla.org needed
| Status | New | ⇒ | Pending |
| Category | ⇒ | NPM Change |
I have tested this item ✅ successfully on 7e2ee6d
I have tested this item ✅ successfully on 7e2ee6d
Tested on npm 11.18.0.
The last lines had the warning lines before the patch was applied. Then gone
I have tested this item ✅ successfully on 7e2ee6d
Tested on npm 11.18.0.
The last lines had the warning lines before the patch was applied. Then gone
Do the new allow script directives work also with older npm versions where they might not be used? Or do they cause errors or warnings on these older versions? Has anyone checked that?
Do the new allow script directives work also with older npm versions where they might not be used? Or do they cause errors or warnings on these older versions? Has anyone checked that?
Didn't check it with older versions, I had an old version of npm that doesn't show warnings on npm i so needed to update first to see the warnings before applying the PR. Didn't think of that scenario.
I downgraded to npm 10.1 and then ran npm i with this PR. No errors or warnings on completion which is what I would expect as that version will happily process the scripts
| Status | Pending | ⇒ | Ready to Commit |
| Labels |
Added:
NPM Resource Changed
PR-5.4-dev
|
||
RTC
RTC
| Labels |
Added:
RTC
|
||
can we have some more tests on macOS please as there has been a macOS specific change
can we have some more tests on macOS please as there has been a macOS specific change
Thanks for pointing that out, but updating allowScripts will remain an ongoing task in the future anyway. I’ll therefore proceed with the final tests and the merge.
we need to be aware in the future that this can be OS specific
✅ Final test before merge with macOS command line
allow-scripts warnings and one more for fsevents@2.3.3 as I am on macOSnpm approve-scripts --all and and moved the package.json file aside
gh pr checkout 48073
allow-scripts warningsnpm ci is still working| Status | Ready to Commit | ⇒ | Fixed in Code Base |
| Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2026-07-17 10:21:06 |
| Closed_By | ⇒ | muhme |
Dear release manager or maintainer: npm v12 introduces security-related changes to the default behaviour of npm install. This requires the new allowScripts section in the package.json file introduced with this PR.
fsevents for macOS.
Starting with npm v11.16, warnings are shown, while in npm v12 the installation scripts are no longer executed if a version-pinned package is missing from allowScripts.
I have tested this item ✅ successfully on 7e2ee6d
This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/48073.