GitHub is finally tightening up security around npm following multiple attacks




  • GitHub will enforce 2FA and deprecate legacy tokens to improve package publishing security
  • Trusted Publishing will expand, and token-based publishing will be restricted by default
  • Shai-Hulud worm breached npm, prompting removal of over 500 compromised packages

Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to make substantial changes to the security of its platform.

In a blog post, GitHub detailed changes to authentication and publishing, set to go live “in the near future”, with the aim of hardening package publication.

https://cdn.mos.cms.futurecdn.net/2viAsX89eJReYQEQ3i3SwH.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img