⚰️ The npm registry as I knew it is officially dead. False positive rates for malware scanning are known to be astronomically high. That's because one attacker's malware is another developer's feature github.blog/changelog/20...
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
github.blog