Strongly recommend this post on npm’s staged publishing change after supply-chain turmoil. npm will roll out staged publishing to add a review step before releases go live after the Shai-Hulud attacks, giving maintainers a chance to catch bad releases.

Read it here: socket.dev/blog/npm-to-impleme

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/feross/statuses/115855581869766909 on your instance and quote it. (Note that quoting is not supported in Mastodon.)