Fetching from the wire…
Public story · 2026-07-30 · high
Npm v12 also disables install scripts by default, and Dependabot added a three-day cooldown on version updates in July.
Why now: GitHub published the rundown on July 28, tying together changes rolled out from May's staged publishing through July's Dependabot cooldown.
GitHub locks high-impact npm accounts into a 72-hour read-only mode after a credential change, per its July 28 security rundown.
The freeze targets account takeover, when stolen credentials let an attacker push a malicious version of a popular package before anyone notices. Three days of forced read-only status gives maintainers time to catch the swap.
Staged publishing landed in May, the first of several changes GitHub stacked through the year.
Npm v12 shipped in June and turns off install scripts by default, closing a technique attackers use to run code the moment a package installs.
Dependabot added a three-day cooldown on version updates in July, delaying how fast it suggests a bump to a version that's only hours old.
GitHub's CI product picked up parallel changes: safer pull_request_target defaults, new workflow execution policies, and a read-only Actions cache for untrusted triggers. A network firewall is still in technical preview.
Install scripts off by default in npm v12 stops more attacks than the 72-hour freeze, since malicious scripts run before any alert can matter. Watch whether GitHub reports install-script abuse dropping since scripts became opt-in.
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Shared topic / Earlier coverage
Both cover GitHub, July; reported by the same outlet (github.blog); overlapping topics (change, hour).
Both cover Actions, GitHub; reported by the same outlet (github.blog); overlapping topics (action, credential).
Both cover Actions, GitHub; reported by the same outlet (github.blog); overlapping topics (action, hour).
Shared entities / Same source domain / Earlier coverage / Tension
Both cover GitHub, July; reported by the same outlet (github.blog); earlier GitHub coverage from 2026-07-29.
Shared entities / Shared topic / Earlier coverage
Both cover Dependabot, GitHub; overlapping topics (cooldown, dependabot); earlier Dependabot coverage from 2026-07-28.
Shared entities / Same source domain / Earlier coverage
Both cover GitHub, July; reported by the same outlet (github.blog); earlier GitHub coverage from 2026-07-27.
Both cover Actions, GitHub; reported by the same outlet (github.blog); earlier Actions coverage from 2026-07-26.
Both cover GitHub, July; reported by the same outlet (github.blog); earlier GitHub coverage from 2026-07-26.