GitHub — npm publish-time malware scanning and dual-use metadata

npm publish-time malware scanning and dual-use metadata

As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement… T…

Added 2
  • npm now performs automatic scanning of packages at publish time as part of supply-chain security improvements
  • A new metadata requirement has been introduced for npm package publishing
View original

Upgraded? How did it go?

Discussion