The release of npm v12 addresses software supply chain risks by blocking dependency lifecycle scripts by default, requiring developer approval to run. While this security improvement mitigates common install-time attacks, experts warn that attackers may shift to runtime threats and caution against inevitable developer approval fatigue.