GitHub Blog
Read post

Disrupting supply chain attacks on npm and GitHub Actions

GitHub has shipped multiple security improvements to npm and GitHub Actions targeting supply chain attack techniques. Key changes include: npm's 72-hour read-only mode for high-impact accounts after sensitive changes, safer pull_request_target defaults to prevent pwn requests, read-only Actions cache for untrusted triggers, staged publishing for npm requiring additional 2FA approval, npm v12 disabling install scripts by default, Dependabot's new 3-day cooldown before opening version update PRs, CircleCI support for npm trusted publishing, an Actions network firewall in technical preview, and expanded self-service credential revocation APIs. These mitigations address the full attack chain from initial compromise through credential exfiltration and malware propagation.

    #security#cicd#github-actions#npm
Jul 28•8m read time•From github.blog
Post cover image
Table of contents
Anatomy of supply chain attacksInitial compromiseExfiltrate credentialsPropagating the attackIdentifying and responding to supply chain attacksWhat’s Next?Tags:Written by
4.7K Impressions1 Comment
GitHub Blog's image
GitHub Blog

The GitHub Blog provides updates, announcements, and insights from the world's leading software deve...

1.4K Followers

•

3K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard