Staged publishing and new install-time controls for npm

(github.blog)

40 points | by brianmcnulty 11 hours ago ago

3 comments

  • koinedad 5 hours ago ago

    Nice…maybe will help some of the recent attacks

    • turkeyboi 4 hours ago ago

      If maintainers actually use it

      • Klaster_1 3 hours ago ago

        This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?