{"podcast":{"title":"Risky Business Features","slug":"risky-business-features-7716365","podcast_index_feed_id":7716365,"rss_url":"https://risky.biz/feeds/risky-business-features/","website_url":"https://risky.biz/","image_url":"https://risky.biz/static/img/rb-feed-features.png","author":"Risky.biz","episode_count":32,"summary":"Join reformed CTO James Wilson as he dives deep on cybersecurity topics through an enterprise lens. From solo content and interviews with CISOs and researchers to vendor and startup deep dives, James does a bit of everything.","last_synced_at":"2026-07-16T16:20:32.872024+00:00","page_url":"https://stenobird.com/podcast/risky-business-features-7716365"},"episode":{"title":"Why NPM v12 won’t stop supply chain attacks","slug":"why-npm-v12-won-t-stop-supply-chain-attacks","published_at":"2026-06-12T07:28:50+00:00","page_url":"https://stenobird.com/podcast/risky-business-features-7716365/why-npm-v12-won-t-stop-supply-chain-attacks","show_page_url":"https://stenobird.com/podcast/risky-business-features-7716365","url":"https://risky.biz/RBFEATURES26/","audio_url":"https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBFEATURES26.mp3","summary":"In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain attack mitigations coming in NPM v12. NPM disabling (by default) auto-run install scripts and dynamic dependencies is a positive step forward… but it’ll take years for this new version to be adopted, and these changes do nothing to prevent malicious packages being imported into projects. Further, Paul thinks disabling these features by default will introduce friction that will cause them to be re-enabled. When the choice is “this builds” and “this is less prone to malware”, the former will always win.","meta_description":"In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain attack mitigations…","key_points":[],"chapters":[],"topics":[],"duration_seconds":2312,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/risky-business-features-7716365/episodes/why-npm-v12-won-t-stop-supply-chain-attacks/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/risky-business-features-7716365/why-npm-v12-won-t-stop-supply-chain-attacks.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}