Multiple trusted publishing configurations for npm
GAVerifiedAdded Sep 22, 2026
We’re continuing to make trusted publishing smoother for npm publishers, guided by maintainers feedback. Three updates to npm publishing are now generally available: Multiple trusted publishing configurations per package Staged packages can only be approved after malware scanning is complete Maintainers can see their staged history in the package versions...
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 8 | Automatic Dependabot access to GitHub-hosted registries Update | Update |
| Sep 9 | npm extends recovery-code security holds to all accounts Update | Update |
| Sep 9 | CodeQL 2.27.0 adds support for Linux ARM64 Update | Update |
| Sep 9 | GitHub Advanced Security expands trial availability Update | Update |
| Sep 9 | Block pull requests with exposed secrets from merging Preview | Preview |
| Sep 9 | Remediate Code Quality findings with agentic autofix Update | Update |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Aug 25 | Block users directly from security advisories Update | Update |