{"version":"2.1.290","anchor":"npm-config-ignore-scriptstrue-env-for-a-spawned-process","canonical_anchor":"npm-config-ignore-scriptstrue-env-for-a-spawned-process","heading":"A process Claude Code starts now has npm install scripts turned off differently","tier":"internal","area":"Plugins","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/npm-config-ignore-scriptstrue-env-for-a-spawned-process","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### A process Claude Code starts now has npm install scripts turned off differently\n\nClaude Code builds an environment with `npm_config_ignore_scripts` set to true for a process it starts, now in a changed way\n\n**Unclear.** Which process is started this way is not known.\n\n**What**\n\nWhen Claude Code starts a certain process, it gives it an environment with `npm_config_ignore_scripts` set to `true`. That tells npm, the JavaScript package tool, not to run the scripts packages carry for install and other steps. The way this environment is put together has changed: it is built from a base set of variables plus this one, and in some cases it is not merged with the rest of Claude Code's own environment.\n\n**Why**\n\nBlocking package scripts is a safety step, because install scripts can run arbitrary commands on your machine.\n\n- Area: Plugins\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}