npm publish-time malware scanning and dual-use metadata
UpdateVerifiedAdded Sep 22, 2026
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time . This changelog covers what publishers can expect and a new metadata requirement for dual-use content.
Topics: Governance, Security, Observability
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jul 28 | Dependabot alerts on malicious packages across more ecosystems Update | Update |
| Jul 29 | CodeQL 2.26.1 improves analysis accuracy and framework coverage Update | Update |
| Jul 31 | Restricting npm bypass-2FA granular access tokens Update | Update |
| Aug 4 | Customize code scanning default setup at scale Update | Update |
| Aug 4 | Customize Dependabot pull request branch names Update | Update |
| Aug 4 | Code coverage automatic enablement in Code Quality settings Preview | Preview |
| Aug 4 | CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support Update | Update |
| Jul 20 | GitHub Code Quality is now generally available GA | GA |