npm extends recovery-code security holds to all accounts
UpdateVerifiedAdded Sep 22, 2026
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts. During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused.
Topics: Security, Observability
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 9 | CodeQL 2.27.0 adds support for Linux ARM64 Update | Update |
| Sep 9 | GitHub Advanced Security expands trial availability Update | Update |
| Sep 9 | Block pull requests with exposed secrets from merging Preview | Preview |
| Sep 9 | Remediate Code Quality findings with agentic autofix Update | Update |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Sep 8 | Automatic Dependabot access to GitHub-hosted registries Update | Update |
| Sep 15 | Enforce GitHub Advanced Security configurations Update | Update |
| Sep 3 | Multiple trusted publishing configurations for npm GA | GA |