Daily Tech News, Interviews, Reviews and Updates

GitHub announces latest npm security improvements due to rise in malicious incidents

Microsoft-owned GitHub this week declares its latest npm security improvements, because of the increase in incidents that includes malicious npm packages.

The latest improvements follow the start of an enhanced verification for npm accounts that was declared in March and accompanying the mandatory two-factor authentication feature that the code-sharing platform has been rolling out over the past couple of months.

After launching the new two-factor authentication experience in beta, GitHub is now making it available in npm 8.15.0, as an opt-in feature – it will become the default in npm 9.

With the latest experience, login and publishing are managed in the browser, so that users could log in to an existing session by providing the second factor or email verification only, while also being able to publish multiple times by using the same IP and access token without seeing the two-factor authentication prompt for five minutes.

Developers can now also link their npm accounts with their GitHub and Twitter accounts, courtesy of new integrations on both platforms, which will be easy for verifying accounts and recovery.

GitHub says We will no longer be showing the previously unverified GitHub or Twitter data on public user profiles, making it possible for developers to audit identities and trust that an account is who they say they are.



Readers like you help support The Tech Outlook. When you make a purchase using links on our site, we may earn an affiliate commission. We cannot guarantee the Product information shown is 100% accurate and we advise you to check the product listing on the original manufacturer website. Thetechoutlook is not responsible for price changes carried out by retailers. The discounted price or deal mentioned in this item was available at the time of writing and may be subject to time restrictions and/or limited unit availability. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates Read More
You might also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More