Skip to content

npm publish-time malware scanning and dual-use metadata

UpdateVerifiedAdded Sep 22, 2026

As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time . This changelog covers what publishers can expect and a new metadata requirement for dual-use content.

Topics: Governance, Security, Observability

GitHub's release notes

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

Every GitHub Advanced Security release

Also shipped on Jul 28, 2026

GitHub in July 2026

Weekly: the week's data and AI releases, Tuesday mornings.