npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
The Hacker News·
Originalartikel lesen bei The Hacker NewsGitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on...
MITRE ATT&CK Kill Chain (1 Techniken)
Reconnaissance