Disrupting supply chain attacks on npm and GitHub Actions
GitHub and npm announced a coordinated set of supply-chain hardening measures deployed over the past year to disrupt common attack patterns targeting open-source maintainers and CI/CD pipelines. Changes include account protection delays for high-impact npm accounts, safer pull_request_target defaults in GitHub Actions, staged publishing, disabled install scripts by default in npm v12, Dependabot version cooldowns, and credential revocation tooling for incident response.