None
ID
GitHub Aims to Secure Supply Chain as NPM Hacks Ramp Up
['Alexander Culafi', 'Senior News Writer', 'Dark Reading']
darkreading
GitHub this week committed to a more secure NPM supply chain in the wake of a handful of attacks causing widespread compromise.
On Sept. 22, GitHub senior director of security research Xavier René-Corail published a blog post to GitHub addressing the surge in package registry-based attacks, specifically NPM packages.
In addition to these actions, GitHub said it would take steps to harden the NPM supply-chain and make package publication more secure.
GitHub Aims to Secure NPM Supply ChainGitHub highlighted three core changes.
"We recognize that some of the security changes we are making may require updates to your workflows," René-Corail wrote.
['changes'
'tokens'
'shaihulud'
'chain'
'ramp'
'secure'
'package'
'aims'
'hacks'
'packages'
'publishing'
'security'
'supply'
'npm'
'github'
'attacks']