GitHub is finally tightening up security around npm following multiple attacks

zeeforce
3 Min Read




  • GitHub will enforce 2FA and deprecate legacy tokens to improve package publishing security
  • Trusted Publishing will expand, and token-based publishing will be restricted by default
  • Shai-Hulud worm breached npm, prompting removal of over 500 compromised packages

Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to make substantial changes to the security of its platform.

In a blog post, GitHub detailed changes to authentication and publishing, set to go live “in the near future”, with the aim of hardening package publication.



Source link

Share This Article
Leave a comment
Optimized by Optimole
Verified by MonsterInsights