Security & TrustSubscribers only 43 min ago7Add to bookmarks

GitHub details the defenses it has implemented in recent months on npm and GitHub Actions: signed publication, hardened tokens, enhanced isolation. A direct counterattack to the wave of 2025-2026 attacks.
In plain terms - GitHub is shipping a batch of hardening changes to npm and GitHub Actions after months of high-profile supply-chain attacks. Signed publishes, tightened tokens, tighter workflow isolation. Painful for lazy pipelines, worth it.
The npm + GitHub Actions chain concentrates an overwhelming share of JavaScript CI/CD - and therefore an increasing share of targeted attacks, notably via maintainer token compromises. GitHub, owner of both platforms, published on July 28, 2026 a retrospective post on the changes "shipped over the past few months" aimed at disrupting these techniques. The move is part of a broader access hardening (see also the mandatory 2FA for all developers who commit, effective September 2, 2026 - publi #1400).
According to the official post (github.blog/security), the defenses cover three areas:
An attestation links a published artifact (npm package) to its build process - workflow, commit, environment - in a verifiable manner on the consumer side. It is the fundamental building block of the SLSA framework (Supply-chain Levels for Software Artifacts) promoted by the Linux Foundation.
In concrete terms, a maintainer can now publish from a signed Actions workflow, with a verifiable attestation. This breaks the class of attacks "signed package but pushed outside the repo": the traceability between the package and the original commit becomes auditable.
Three signals to remember. First, the attack surface has shifted from the repo to the pipeline: compromising a maintainer token or a CI runner now gives more than direct access to the source code. Then, GitHub is moving smoothly - new rules coexisting with the old model, gradual migration, no brutal breakage. Finally, the dominant platform de facto imposes its doctrine: GitLab, Bitbucket, and the Sonatype ecosystem will have to align or lose enterprise credibility.
For a backend lead: configure trusted publishing from Actions, enable attestations on your release workflows. For a platform engineer: check your self-hosted runners, often less hardened than GitHub's hosted ones. For a CISO: add attestation verification to your release pipeline before your clients demand it.
Counter of attestations on top npm packages in the coming months, first documented attack attempt post-hardening, alignment (or not) of PyPI and Cargo on the same model.
Create a free account to access all our content and the weekly review.
Article produced by artificial intelligence, reviewed under human editorial control.
Sign in to join the discussion.
How will these new security measures affect the open-source community's collaborative spirit? Will it stifle innovation or foster safer development practices?
I wonder if these measures will be enough to stop the supply-chain attacks. The attackers are getting more sophisticated every day.
It's a constant arms race, but improved security measures can help tip the balance in our favor.
I'm glad to see GitHub taking proactive steps to secure npm and Actions. It's about time they addressed these vulnerabilities head-on.
I wonder how these new measures will affect the speed of development. Will they slow down the workflow for legitimate developers?
I'm curious about the impact on smaller projects. Will these new measures add unnecessary complexity for developers?
I'm curious about the impact on small developers. Will these measures make it harder for them to contribute to open-source projects?
I hope these new security measures will indeed make a difference. It's crucial for open-source platforms to stay ahead of these evolving threats.
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions