Sign in

npm

@npmjs.com
159 followers 2 following 10 posts

The package manager for JavaScript Problems? Visit npmjs.com/support or github.com/npm/feedback

PostsRepliesMedia
npm @npmjs.com · 28/09/2026
Automate preparation, keep approval with a maintainer. npm’s stage-only granular access tokens let CI stage new versions, while publication requires maintainer approval with 2FA. Get started ⬇️
github.blog
Stage-only npm tokens for safer automation - GitHub Changelog
You can now select Read and write (stage only) when creating an npm granular access token. This lets your automated workflows stage package versions for review without giving the token…
033
npm @npmjs.com · 21/09/2026
The latest updates on npm 🧵⬇️
1196
npm @npmjs.com · 13/08/2026
npm Granular Access Tokens that bypass 2FA can no longer manage your account, org, or packages—those actions now require an interactive 2FA challenge, closing a major credential-based attack surface. github.blog/changelog/20...
github.blog
Restricting npm bypass-2FA granular access tokens - GitHub Changelog
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of…
1254
npm @npmjs.com · 04/08/2026
npm is rotating write-scoped npm Granular Access Tokens that bypass 2FA as a precaution following a now-contained security incident. This doesn't affect GitHub personal access tokens. Maintainers should upgrade the npm CLI to v12+ and consider Trusted Publishing. docs.npmjs.com/trusted-publ...
docs.npmjs.com
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
13014
npm @npmjs.com · 29/07/2026
Strengthening npm supply-chain security: packages are now scanned for malware at publish time, before they can be installed. We're also introducing disclosure for legitimate dual-use tools so they aren't blocked by default. gh.io/npm-publish-...
gh.io
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
0227
npm @npmjs.com · 08/07/2026
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
26024