
- GitHub will enforce 2FA and deprecate legacy tokens to improve package publishing security
- Trusted Publishing will expand, and token-based publishing will be restricted by default
- Shai-Hulud worm breached npm, prompting removal of over 500 compromised packages
Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to make substantial changes to the security of its platform.