From a3d7de4fa474f9683a46450f1f7b27f3b8571ce0 Mon Sep 17 00:00:00 2001 From: Abdirahim Musse <33973272+abmusse@users.noreply.github.com> Date: Thu, 2 Jul 2026 16:49:30 -0500 Subject: [PATCH 1/6] doc: update npm install steps With npm v12. `npm install` will no longer automatically run scripts from your package dependencies, but instead must be explicitly marked as allowed/trusted. This is to reduce the potential for malware and the effect of other recent supply chain attacks to be performed. node-odbc uses node-pre-gyp to automatically install a pre-built node binding from the corresponding GitHub release or fall back to building it from source if a pre-built is not available. Starting with npm v12, the node-pre-gyp install script will no longer be run unless explicitly allowed using `npm approve-scripts odbc`. Fixes #478 --- README.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/README.md b/README.md index 7559fa1..8625455 100644 --- a/README.md +++ b/README.md @@ -55,6 +55,11 @@ Three main steps must be done before `node-odbc` can interact with your database When all these steps have been completed, install `node-odbc` into your Node.js project by using: ```bash +# node-odbc uses node-pre-gyp install scripts +# npm v12+ requires approval for install scripts to run +# https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/ +npm --approve-scripts odbc + npm install odbc ``` --- From 4268c2e10f38e20e8fb30674fc16baadc261190a Mon Sep 17 00:00:00 2001 From: Abdirahim Musse <33973272+abmusse@users.noreply.github.com> Date: Wed, 23 Sep 2026 13:23:05 -0500 Subject: [PATCH 2/6] fixup! --- README.md | 23 ++++++++++++++++++----- 1 file changed, 18 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 8625455..c0fe8f9 100644 --- a/README.md +++ b/README.md @@ -55,13 +55,26 @@ Three main steps must be done before `node-odbc` can interact with your database When all these steps have been completed, install `node-odbc` into your Node.js project by using: ```bash -# node-odbc uses node-pre-gyp install scripts -# npm v12+ requires approval for install scripts to run -# https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/ -npm --approve-scripts odbc - npm install odbc ``` + +--- +**NOTE:** starting with version 12, npm will no longer run install scripts by default. When installing, you will see a message like this: + +```sh +npm warn install-scripts odbc@2.5.0 (install: node-pre-gyp install --fallback-to-build) +``` + +We use [node-pre-gyp](https://github.com/mapbox/node-pre-gyp) to build and install a prebuilt binary with the package. +For the prebuilt binary to get installed you need to approve the install script and re-trigger the install script. + +```bash +npm approve-scripts odbc +npm rebuild odbc +``` + +For more information refer to the [npm blog post](https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/). + --- ## Debugging From c90689c979597340fcabaee429d75455b103c462 Mon Sep 17 00:00:00 2001 From: Abdirahim Musse <33973272+abmusse@users.noreply.github.com> Date: Wed, 23 Sep 2026 13:27:11 -0500 Subject: [PATCH 3/6] Add alert emoji --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index c0fe8f9..73ede76 100644 --- a/README.md +++ b/README.md @@ -59,6 +59,8 @@ npm install odbc ``` --- +🚨🚨🚨 + **NOTE:** starting with version 12, npm will no longer run install scripts by default. When installing, you will see a message like this: ```sh From 36f64df3842301cb80559f1152318a1e53c42ff8 Mon Sep 17 00:00:00 2001 From: Abdirahim Musse <33973272+abmusse@users.noreply.github.com> Date: Wed, 23 Sep 2026 13:46:25 -0500 Subject: [PATCH 4/6] fixup! --- README.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 73ede76..c1083b5 100644 --- a/README.md +++ b/README.md @@ -68,7 +68,10 @@ npm warn install-scripts odbc@2.5.0 (install: node-pre-gyp install --fallback- ``` We use [node-pre-gyp](https://github.com/mapbox/node-pre-gyp) to build and install a prebuilt binary with the package. -For the prebuilt binary to get installed you need to approve the install script and re-trigger the install script. +You will need to approve the install script and re-trigger the install script. +This only needs to be done once. +After it's been approved and package.json updated, then they won't need to do anything else. +Future updates should just work. ```bash npm approve-scripts odbc From 603ff30ec584194da605a6b77e08784d84c2a6e7 Mon Sep 17 00:00:00 2001 From: Abdirahim Musse <33973272+abmusse@users.noreply.github.com> Date: Wed, 23 Sep 2026 13:47:36 -0500 Subject: [PATCH 5/6] fixup! --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index c1083b5..32137e1 100644 --- a/README.md +++ b/README.md @@ -70,7 +70,7 @@ npm warn install-scripts odbc@2.5.0 (install: node-pre-gyp install --fallback- We use [node-pre-gyp](https://github.com/mapbox/node-pre-gyp) to build and install a prebuilt binary with the package. You will need to approve the install script and re-trigger the install script. This only needs to be done once. -After it's been approved and package.json updated, then they won't need to do anything else. +After it's been approved and package.json updated, there is nothing else to do. Future updates should just work. ```bash From 52fe08327dfc15879f05c9d9c823a1f72595c876 Mon Sep 17 00:00:00 2001 From: Abdirahim Musse <33973272+abmusse@users.noreply.github.com> Date: Wed, 23 Sep 2026 15:04:25 -0500 Subject: [PATCH 6/6] Fixup using suggestions --- README.md | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 32137e1..775b70b 100644 --- a/README.md +++ b/README.md @@ -67,16 +67,14 @@ npm install odbc npm warn install-scripts odbc@2.5.0 (install: node-pre-gyp install --fallback-to-build) ``` -We use [node-pre-gyp](https://github.com/mapbox/node-pre-gyp) to build and install a prebuilt binary with the package. -You will need to approve the install script and re-trigger the install script. -This only needs to be done once. -After it's been approved and package.json updated, there is nothing else to do. -Future updates should just work. +We use [node-pre-gyp](https://github.com/mapbox/node-pre-gyp) to download prebuilt binaries or build from source for platforms which don't have prebuilt binaries. +You will need to approve the install script in order to use the odbc package. After approval, you will need to re-trigger the install script for odbc to work. ```bash npm approve-scripts odbc npm rebuild odbc ``` +Once it has been approved and your package.json is updated, future installs will just work. For more information refer to the [npm blog post](https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/).