Hacker News
GitHub Details Its npm Supply-Chain Lockdown: 72-Hour Read-Only Accounts, Install Scripts Off by Default in npm v12
GitHub published a 2026-07-28 rundown (88 points, 40 comments) of defenses shipped across 2026 against npm and Actions supply-chain attacks. High-impact npm accounts now enter read-only mode for 72 hours when credentials change, staged publishing landed in May, npm v12 disables install scripts by default as of June, and Dependabot added a three-day version-update cooldown in July. Actions-side changes include safer pull_request_target defaults, workflow execution policies, read-only Actions cache for untrusted triggers, and a network firewall in technical preview.
↳ Follow the thread