# GitHub npm publish-time malware scanning and dual-use metadata - Product: GitHub (https://whatsnew.fyi/product/github) - Vendor: GitHub - Date: 2026-07-28 - Original notes: https://github.blog/changelog/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-metadata - Permalink: https://whatsnew.fyi/product/github/releases/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-me What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement… T… - **added** — npm now performs automatic scanning of packages at publish time as part of supply-chain security improvements - **added** — A new metadata requirement has been introduced for npm package publishing