A good software architecture ensures that an AI system does not depend on the performance of a specific model.
With npm v12, GitHub closes a central attack vector: installation scripts from dependencies will only run after explicit approval from July 2026.