GitHub is finally tightening up security around npm following multiple attacks

GitHub is finally tightening up security around npm following multiple attacks

GitHub is finally tightening up security around npm following multiple attacks


  • GitHub will enforce 2FA and deprecate legacy tokens to improve package publishing security
  • Trusted Publishing will expand, and token-based publishing will be restricted by default
  • Shai-Hulud worm breached npm, prompting removal of over 500 compromised packages

Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to make substantial changes to the security of its platform.

In a blog post, GitHub detailed changes to authentication and publishing, set to go live “in the near future”, with the aim of hardening package publication.



Source link

Back To Top