Sign in

leobalter.bsky.social

@leobalter.bsky.social
58 followers 56 following 7 posts
PostsRepliesMedia
Reposted by @leobalter.bsky.social
npm @npmjs.com · 01/10/2026
Manage npm dist-tags with Trusted Publishing, without keeping a separate token for the job. Opt in per configuration, including staging-only workflows. Existing permissions stay unchanged unless you enable it. Learn more ⬇️
github.blog
Opt-in dist-tag permissions for npm trusted publishing - GitHub Changelog
Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials in...
032
Reposted by @leobalter.bsky.social
npm @npmjs.com · 28/09/2026
Automate preparation, keep approval with a maintainer. npm’s stage-only granular access tokens let CI stage new versions, while publication requires maintainer approval with 2FA. Get started ⬇️
github.blog
Stage-only npm tokens for safer automation - GitHub Changelog
You can now select Read and write (stage only) when creating an npm granular access token. This lets your automated workflows stage package versions for review without giving the token…
033
Reposted by @leobalter.bsky.social
npm @npmjs.com · 21/09/2026
The latest updates on npm 🧵⬇️
1196
leobalter.bsky.social @leobalter.bsky.social · 28/08/2026
www.linkedin.com/pulse/securi...
linkedin.com
Securing npm without breaking the web
A year of self-propagating supply-chain attacks at the world's largest package registry — and why the fix was the easy part. I'm the Senior Product Manager for npm at GitHub.
000
Reposted by @leobalter.bsky.social
npm @npmjs.com · 04/08/2026
npm is rotating write-scoped npm Granular Access Tokens that bypass 2FA as a precaution following a now-contained security incident. This doesn't affect GitHub personal access tokens. Maintainers should upgrade the npm CLI to v12+ and consider Trusted Publishing. docs.npmjs.com/trusted-publ...
docs.npmjs.com
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
13014
Reposted by @leobalter.bsky.social
npm @npmjs.com · 29/07/2026
Strengthening npm supply-chain security: packages are now scanned for malware at publish time, before they can be installed. We're also introducing disclosure for legitimate dual-use tools so they aren't blocked by default. gh.io/npm-publish-...
gh.io
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
0227
Reposted by @leobalter.bsky.social
npm @npmjs.com · 08/07/2026
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
26024
Reposted by @leobalter.bsky.social
daniel wraith @danielroe.dev · 22/05/2026
💥 just released a github action: `uppt` it aims to be a very simple, secure release workflow for maintainers that adheres to best security practices ⚪ trusted, staged publishing on npmjs.com ⚪ github environment protection ⚪ generated release PR + changelog ⚪ automatic release + publish on merge ✨
1116228
Reposted by @leobalter.bsky.social
GitHub @github.com · 17/12/2024
Prepare to take flight 👀
1817119
Reposted by @leobalter.bsky.social
Julia Adult @juliaadult.bsky.social · 05/12/2024
Whooooaaaaa black Betty
193070513