GitHub added npm staged publishing with mandatory 2FA approval to reduce software supply chain attack risks.

Today we’re shipping two updates focused on supply-chain security for npm: Staged publishing is generally available. New --allow-* install source flags (--allow-file,…

GitHub added npm staged publishing with mandatory 2FA approval to reduce software supply chain attack risks.