Fetching from the wire…
Public story · 2026-07-30 · high
Npm v12 also disables install scripts by default, and Dependabot added a three-day cooldown on version updates in July.
Why now: GitHub published the rundown on July 28, tying together changes rolled out from May's staged publishing through July's Dependabot cooldown.
GitHub locks high-impact npm accounts into a 72-hour read-only mode after a credential change, per its July 28 security rundown.
The freeze targets account takeover, when stolen credentials let an attacker push a malicious version of a popular package before anyone notices. Three days of forced read-only status gives maintainers time to catch the swap.
Staged publishing landed in May, the first of several changes GitHub stacked through the year.
Npm v12 shipped in June and turns off install scripts by default, closing a technique attackers use to run code the moment a package installs.
Dependabot added a three-day cooldown on version updates in July, delaying how fast it suggests a bump to a version that's only hours old.
GitHub's CI product picked up parallel changes: safer pull_request_target defaults, new workflow execution policies, and a read-only Actions cache for untrusted triggers. A network firewall is still in technical preview.
Install scripts off by default in npm v12 stops more attacks than the 72-hour freeze, since malicious scripts run before any alert can matter. Watch whether GitHub reports install-script abuse dropping since scripts became opt-in.
Each link below shares sources, entities, or timing with this story.
The August 13 availability report covers eight incidents. July 8 ran 7 hours 4 minutes at ~96% error rate across Web UI, REST/GraphQL, Actions, Packages, Copilot and Git operations after an automated infrastructure process changed runtime config and broke service discovery. A...
GitHub's July 23 changelog reports the stateless core let them remove the Redis session dependency and the deep packet inspection of request payloads, with elicitation upgraded to multi-round-trip HTTP wrapped by the SDKs. They use the official Go SDK and required no changes;...
GitHub expanded Copilot's Rubber Duck mode with something that caught my attention: cross-family review. Claude now critiques GPT-authored sessions. GPT-5.5 reviews Claude sessions. Two different model families, trained on different data with different failure modes, checking...
Every Node.js project you've ever touched probably depends on Axios. On March 31, a compromised npm maintainer account pushed backdoored versions 1.14.1 and 0.30.4 that silently installed a cross-platform remote access trojan on macOS, Windows, and Linux. The attack chain was...
GitHub shipped it July 28 across Pro through Enterprise, reachable from VS Code, Visual Studio, Copilot CLI, the cloud agent, JetBrains, Xcode, and Eclipse, with text and image inputs and low/medium/high reasoning effort, billed at provider list pricing rather than a fixed mul...
ZhuLinsen/daily_stock_analysis carries an 84% fork ratio, about eight times anything else on today's trending set, because the recommended install path isn't clone. Users fork, add an AI key and a notification credential to Actions Secrets, enable Actions, and the analysis run...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.