GitHub is finally tightening security around NPM after multiple attacks


  • GitHub will enforce 2FA and write off older tokens to improve the packaging security of the packaging
  • Trusted Publishing will expand and token-based publishing will be limited by default
  • Shai-Hulud Worm violated NPM, which resulted in the removal of over 500 compromised packages

After a series of recent high -profile attacks and hacking attempts, GitHub has decided to make significant changes in security on its platform.

In a blog post detailed GitHub changes for approval and release to go live “in the near future” for the purpose of publication of curing package.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top