惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
G
GRAHAM CLULEY
P
Privacy & Cybersecurity Law Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
H
Help Net Security
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
C
Cisco Blogs
人人都是产品经理
人人都是产品经理
Know Your Adversary
Know Your Adversary
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Recorded Future
Recorded Future
I
Intezer
罗磊的独立博客
T
The Exploit Database - CXSecurity.com
Blog — PlanetScale
Blog — PlanetScale
Malwarebytes
Malwarebytes
Spread Privacy
Spread Privacy
T
Tor Project blog
V
Vulnerabilities – Threatpost
云风的 BLOG
云风的 BLOG
腾讯CDC
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
F
Future of Privacy Forum
MyScale Blog
MyScale Blog
Latest news
Latest news
IT之家
IT之家
MongoDB | Blog
MongoDB | Blog
The Hacker News
The Hacker News
S
Securelist
博客园 - 【当耐特】
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threat Research - Cisco Blogs
Jina AI
Jina AI
Cisco Talos Blog
Cisco Talos Blog
B
Blog
博客园 - 三生石上(FineUI控件)
Last Week in AI
Last Week in AI
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
M
MIT News - Artificial intelligence
V
V2EX
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Cloudflare Blog
The GitHub Blog
The GitHub Blog
博客园 - 聂微东
F
Full Disclosure
C
CERT Recently Published Vulnerability Notes

The Register

HackerOne takes an axe to its bug bounty rewards AI is getting pricey, but relief is coming, but not for you Deus ex machina: Half of US Christians trust AI's spiritual advice Flipper One wants to be the Linux multi-tool in your pocket Web devs sleeping with the enemy: AI is doing their job and they worry it's after their desk too AWS parades orgs that took up its offer for Euro Sovereign Cloud Years after UK Post Office scandal broke, Accenture and OneView Commerce bag contract to replace Horizon Gemini accused of 30,000-line code purge and fake recovery report Minecraft-streaming gran swatted while raising cash for grandson's cancer care 46k plaintext passwords pwned in Myspace93 breach Vivaldi 8 polishes the chrome without coating it in AI Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw Apple adds AI smarts to Voice Control, VoiceOver and Magnifier ahead of Accessibility Day Microsoft open-sources agentic AI safety tools Think tank to UK government: You can't build the future on systems from the past UK.gov hikes health AI tender by 400% – and hundreds of millions – after a chat with suppliers UK’s Education Committee: Social media ban a must to save children’s mental health Zombie user account let hackers control the city’s water Open Compute urges local government to bask in the warm glow of excess datacenter heat SpaceX pitches itself as integrated interplanetary proto-monopolist in IPO filing Nvidia on track to be worlds leading CPU supplier claims CFO AMD says its $4K Ryzen AI Halo workstation practically pays for itself Intuit axes 3,000 – without blaming AI AI code accelerates production failures and spending, study finds Even Claude agrees: hole in its sandbox was real and dangerous Intel's CEO reveals early hiring challenges as bankruptcy concerns deterred top talent OpenAI floats buy-before-your-try AI availability guarantee Microsoft rebases Azure Linux on Fedora as Fedora drops Deepin Bye-bye, Gemini CLI; Google nudges devs toward Antigravity Plex appeal fades as Lifetime Pass jumps to $750 Those spared latest Meta job cuts forcibly reassigned to AI roles Datacenter builds could be shielded from judicial review in UK planning reforms Microsoft says cu l8r to text message security 'Workforce rebalancing' comes for Kyndryl, and delivery teams are in the firing line AMD says its $4K Ryzen AI Halo workstation practically pays for itself ESA boss tires of being dragged around by NASA mood swings GitHub says internal repos exfiltrated after poisoned VS Code extension attack Smaller suppliers invited to pitch for £2.9B UK defense tech framework PostgreSQL backup tool gets some backup of its own after sole maintainer sounds alarm London's police asked Big Tech for comms data over 700,000 times last year ZTE releases Sustainability Report 2025: driving a new chapter in sustainable development through AI Space factories edge closer after experimental capsule survives hypersonic landing Google Cloud suspended major customer Railway.com without cause, causing outage AI sackings reach New Zealand, which will use it to eject 14 percent of government staff Anthropic’s Stainless steal tightens grip on AI dev tooling Google accused of pushing 'free for life' G Suite users onto paid plans Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware Frustrated franchisee sues Pizza Hut over crappy kitchen AI Google touts tokenmaxxing, huge capex, and AI agents at I/O Firefox 151 helps you edit PDFs – and switch OSes America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shadow AI invades the workplace, up 4x in the last year Airbus gets HPC-as-a-service supercomputer from Bull Clear your calendar, Drupal user: You have a critically urgent patch to install SAP customers warned AI agents could put costs on autopilot Microsoft refreshes Surface for Business lineup, starts AI PC upsell at $1,499 X limits hot takes from freeloaders to 50 a day Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise Broadcom finds a VMware customer willing to stick around: London Stock Exchange Indra rides off with £1.96B Transport for London ticketing deal as Oyster heads for back-office overhaul 468k records allegedly stolen from Portugal’s postal carrier 1 in 5 Brits think AI layoffs could trigger civil unrest UK Typhoon jets fitted with bargain-bin drone busters for Middle East sorties SAP's AI strategy: Come for the openness, stay because you have to ZTE Showcases AI Interactive Flat Panel at the Broadband User Congress in Brazil Windows Firewall stands between you and greasy delight The class of 2026 has heard enough about AI, thanks Baidu says the quiet part out loud – you can’t build AI infrastructure, so clouds can cash in Iran hints it could interfere with submarine cables in the Strait of Hormuz VMware quietly debuts Arm hypervisor tech preview Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them The big AI companies are going to see their margins disappear Shai-Hulud copycat hits another npm package MAGA's Mace wants to make power bills great again, calls for datacenter moratorium Uncle Sam's next big super might not use GPUs Yes, you can serve a website from a $1 microcontroller Linux kernel flaw opens root-only files to unprivileged users Europe tests laser links as satellite comms outgrow radio Dutch cops’ shame game works wonders as most wanted scammers now turned in 'Big AI' is subverting regulations just like tobacco and oil firms TanStack weighs invitation-only pull requests after supply chain attack Microsoft remembers that taskbars used to move NGINX Rift attackers waste no time targeting exposed servers Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative Windows boot partition runs out of space for Microsoft's May security update F-35 software delays leave UK buying time with US glide bombs Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess Google tells database devs to lean hard on AI for PostgreSQL work Utah tells porn sites to take the P out of VPNs, and it's their fault that they can't Utah tells porn sites to take the P out of VPNs, and it's their fault that they can't Doom soundtrack added to National Recording Registry Backup script ingested an accidental asterisk and deleted everything Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Samsung’s weather app sparks storm of controversy by handing territory to North Korea Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ Surprise AI bills leave AWS and Google Cloud users aghast How AI agent harnesses like OpenClaw are changing LLMs, inference, and CPUs Enough with the AI FOMO, go slow-mo, says Domo CDO Classic 7 is Windows 10 LTSC cosplaying as Windows 7
Npm registry sets stage for more secure package publishing
2026-05-22 · via The Register

AI + ML

All the world's a stage, and all the packages are merely players

GitHub's npm package registry has rolled out a publishing approval step to prevent the distribution of compromised packages before they can poison the software supply chain.

Modern software development relies on imported bundles of code known as packages (and sometimes libraries or modules). In the past decade or so, miscreants have focused on gaining access to the accounts of package maintainers. Subverting a widely used package offers a fast track to malware distribution.

Last December, amid the Shai-Hulud 2.0 campaign that compromised software packages, GitHub described a series of planned security measures intended to harden security for npm package publishers.

REG AD

One of the measures, staged publishing, has now been implemented. GitHub on Wednesday merged npm stage into npm CLI (v11.15.0) and has updated the registry documentation that describes the process.

REG AD

Staged publishing might also be called gated publishing – it requires a project maintainer to approve changes to a package that has been staged for release. It's been under discussion since 2020.

"Instead of publishing directly with npm publish, you can submit packages to a staging area with npm stage publish," the documentation explains. "A maintainer must then review and explicitly approve the staged package — with two-factor authentication (2FA) via the CLI or npmjs.com — before it becomes publicly available."

This process should have particular value for automated workflows, which typically don't include a way to authorize via 2FA. 

Automated workflows often rely on tokens for authentication, but these can be copied and stolen.

Tokens that remain valid for long periods of time become attractive targets for cyberattackers. That's why GitHub did away with long-lived classic tokens and encouraged the use of short-lived session tokens and permission-limited access tokens for automation. 

GitHub's discontinuation of classic tokens hasn't gone all that well because short-lived tokens tend to expire at inconvenient times – no one likes having to regenerate tokens every 90 days or less and then go through the reconfiguration process.

Staged publishing should make it easier for developers to set up maintainable workflows without burdensome re-authentication rituals. It gives package publishers the option to stage their package via automation and to delay the 2FA approval for publishing at a later date. 

GitHub offers trusted publishing as a way to establish trust between npm and the developer's CI/CD provider using OpenID Connect (OIDC) authentication. The OIDC mechanism still doesn't work when trying to publish a package for the first time, but together with staged publishing, the software supply chain looks a bit more defensible – so long as developers avail themselves of these tools. ®