Sign in

npm

@npmjs.com
159 followers 2 following 10 posts

The package manager for JavaScript Problems? Visit npmjs.com/support or github.com/npm/feedback

PostsRepliesMedia
npm @npmjs.com · 40m
Manage npm dist-tags with Trusted Publishing, without keeping a separate token for the job. Opt in per configuration, including staging-only workflows. Existing permissions stay unchanged unless you enable it. Learn more ⬇️
github.blog
Opt-in dist-tag permissions for npm trusted publishing - GitHub Changelog
Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials in...
011
npm @npmjs.com · 28/09/2026
Automate preparation, keep approval with a maintainer. npm’s stage-only granular access tokens let CI stage new versions, while publication requires maintainer approval with 2FA. Get started ⬇️
github.blog
Stage-only npm tokens for safer automation - GitHub Changelog
You can now select Read and write (stage only) when creating an npm granular access token. This lets your automated workflows stage package versions for review without giving the token…
033
npm @npmjs.com · 21/09/2026
Learn more recent improvements and what’s next. Tell us what would make publishing and consuming packages safer and easier.
github.com
npm’s roadmap: safer publishing, smoother workflows, and what’s next · community · Discussion #208130
Hi everyone, Leo here, npm's PM. I want to share what we’ve shipped since May, where we’re focusing for the rest of 2026, and what we’re considering for 2027. I also want your feedback: what would ...
061
npm @npmjs.com · 21/09/2026
npm now has broader account protection. A temporary 72-hour security hold will be placed on any account after a successful recovery-code sign-in. Applicable to all npm accounts.
github.blog
npm extends recovery-code security holds to all accounts - GitHub Changelog
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change appli...
280
npm @npmjs.com · 21/09/2026
npm is making safer publishing easier to adopt. Now generally available: • Multiple trusted publishing configurations per package • Staged packages can only be approved after malware scanning is complete • Maintainers can see their staged history in the package versions tab
github.blog
Multiple trusted publishing configurations for npm - GitHub Changelog
We’re continuing to make trusted publishing smoother for npm publishers, guided by maintainers feedback. Three updates to npm publishing are now generally available: Multiple trusted publishing config...
170
npm @npmjs.com · 21/09/2026
The latest updates on npm 🧵⬇️
1196
npm @npmjs.com · 13/08/2026
Coming next: bypass-2FA tokens will also lose direct publish (~Jan 2027). Move automated publishing to trusted publishing (OIDC) or staged publishing.
131
npm @npmjs.com · 13/08/2026
npm Granular Access Tokens that bypass 2FA can no longer manage your account, org, or packages—those actions now require an interactive 2FA challenge, closing a major credential-based attack surface. github.blog/changelog/20...
github.blog
Restricting npm bypass-2FA granular access tokens - GitHub Changelog
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of…
1254
npm @npmjs.com · 04/08/2026
npm is rotating write-scoped npm Granular Access Tokens that bypass 2FA as a precaution following a now-contained security incident. This doesn't affect GitHub personal access tokens. Maintainers should upgrade the npm CLI to v12+ and consider Trusted Publishing. docs.npmjs.com/trusted-publ...
docs.npmjs.com
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
13014
npm @npmjs.com · 29/07/2026
Strengthening npm supply-chain security: packages are now scanned for malware at publish time, before they can be installed. We're also introducing disclosure for legitimate dual-use tools so they aren't blocked by default. gh.io/npm-publish-...
gh.io
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
0227
npm @npmjs.com · 08/07/2026
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
github.blog
npm install-time security and GAT bypass2fa deprecation - GitHub Changelog
npm v12 is now generally available and tagged latest. This major release turns on the install-time security defaults we announced in June, and it’s also where we begin a deprecation…
26024