Skip to content

npm extends recovery-code security holds to all accounts

UpdateVerifiedAdded Sep 22, 2026

npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts. During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused.

Topics: Security, Observability

GitHub's release notes

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

Every GitHub Advanced Security release

Also shipped on Sep 9, 2026

GitHub in September 2026

Weekly: the week's data and AI releases, Tuesday mornings.