GitHub Fights Back Against npm Supply Chain Attacks with Mandatory 2FA and 7-Day Token Limits
GitHub has announced major security enhancements to its npm package ecosystem in response to sophisticated supply chain attacks, including the recent Shai-Hulud malware that infected hundreds of packages. Key improvements include a revolutionary "trusted publishing" system using cryptograp...
