Skip to main content
Scour
Discover
Docs
Login
Sign Up
Discover
About
Docs
Changelog
You are offline. Trying to reconnect...
Copied to clipboard
Unable to share or copy to clipboard
Back to article
docs.npmjs.com
40w
40 weeks ago
Trusted Publishing for NPM Packages
(opens in new tab)
Covered by
5 sources
See all sources covering this story
including
GitHub
,
thehackernews.com
Discussed on
Hacker News
Love
Like
Not for me
Save
|
|
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Covered in 5 articles
GitHub
·
3w
3 weeks ago
unloopedmido/contextlevy: PR context-cost checks for AI coding agents — bundle-size checks for agent context.
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for unloopedmido/contextlevy: PR context-cost checks for AI coding agents — bundle-size checks for agent context.
thehackernews.com
·
4w
4 weeks ago
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
github.blog
·
4w
4 weeks ago
Staged publishing and new install-time controls for npm
Discussed on
Hacker News
and
Lobsters
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Staged publishing and new install-time controls for npm
Tenable Blog
·
3w
3 weeks ago
Download pumping: New npm deception technique for supply chain attacks
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Download pumping: New npm deception technique for supply chain attacks
neciudan.dev
·
4w
4 weeks ago
https://neciudan.dev/github-actions-poisoning
Discussed on
r/netsec
,
r/node
, and
r/programming
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for https://neciudan.dev/github-actions-poisoning
Keyboard Shortcuts
Navigation
Next / previous post
j
/
k
Open post
o
or
Enter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
g
h
Interests
g
i
Feeds
g
f
Likes
g
l
History
g
y
Changelog
g
c
Settings
g
s
Discover
g
b
Search
/
Pagination
Next page
n
Previous page
p
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc
Press
?
anytime to show this help
Like
Save
Not for me
Report