@leobalter.bsky.social

Strengthening npm supply-chain security: packages are now scanned for malware at publish time, before they can be installed. We're also introducing disclosure for legitimate dual-use tools so they aren't blocked by default. gh.io/npm-publish-...

npm publish-time malware scanning and dual-use metadata - GitHub Changelog

As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…

gh.io

npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...

npm install-time security and GAT bypass2fa deprecation - GitHub Changelog

npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…

github.blog

💥 just released a github action: `uppt` it aims to be a very simple, secure release workflow for maintainers that adheres to best security practices ⚪ trusted, staged publishing on npmjs.com ⚪ github environment protection ⚪ generated release PR + changelog ⚪ automatic release + publish on merge ✨