we just shipped a number of security-focused improvements to npm including:
- naming access tokens
- enforcing 2FA in your npm orgs
- improved auditing for 2FA adoption in orgs
- selecting teams when adding new org members
read more in our Changelog ⬇️ github.blog/changelog/2022-0…
Demo Days is live! Join us to talk complex workflows, managing multiple projects in a single monorepo, securing dependencies and more with the @npmjs CLI.
In case you missed it, the @npmjs CLI has been making big strides lately. Join us this Friday on Demo Days and we’ll deep dive into Workspaces, Overrides and more!
linkedin.com/feed/update/urn…
continuing our commitment to npm security with the introduction of new enhanced login verification and timeline for two-factor authentication enforcement github.blog/2021-12-07-enrol…
today’s open rfc meeting agenda features running `prepare` scripts for linked bundled dependencies, and more!
come and join the conversation 🎙️ github.com/npm/rfcs/issues/4…
an update on recent security incidents across the registry as well as a look into our ongoing investments in maintaining the security of the registry (including 2FA requirements) ⬇️ github.blog/2021-11-15-githu…
following ongoing investigations, we identified in real time multiple versions of the “rc” package containing identical malware to the “coa” package. malicious versions of “rc” were immediately removed from the registry and we have published an advisory: github.com/advisories/GHSA-g…
the compromised account has been temporarily disabled and we are actively investigating the incident and monitoring for similar activity. we will share additional information as appropriate based on our investigation. [2/3]
this morning we detected multiple versions of the “coa” package published with malicious code due to a compromised account of a maintainer. we quickly removed the compromised versions and have published an advisory: github.com/advisories/GHSA-7…. npm itself was not compromised. [1/3]