Replies: 3 comments 2 replies
This comment was marked as spam.
This comment was marked as spam.
-
@leobalter, how could that increase security...? |
Beta Was this translation helpful? Give feedback.
2 replies
-
|
Being forced to have to randomly replace tokens in workflows I don't use that often isn't really cool |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello everyone,
As of today, October 13, 2025, the first set of npm security changes is now in effect following up on our September 29 changelog post and the ongoing community discussion.
Changes now active:
What hasn't changed yet:
Action needed:
Documentation has been updated at docs.npmjs.com to reflect these changes.
As a reminder, this is our first set of security improvements. Classic token revocation and additional changes will follow in November. We'll continue to communicate each phase in advance through this discussion thread and future changelog posts.
Thank you for your patience as we work together to strengthen npm's security. This discussion thread can still be used for general feedback, questions, or concerns about any of the npm security changes.
Beta Was this translation helpful? Give feedback.
All reactions