•1 min read•from InfoQ
GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing


GitHub consolidated the npm and Actions changes it shipped from March to July 2026 against supply chain attacks, several of which alter defaults rather than add options. Hacker News discussion focused less on the individual controls than on whether waiting periods are the right instrument, or a substitute for author-side package signing.
By Steef-Jan WiggersWant to read more?
Check out the full article on the original site
Tagged with
#GitHub
#npm
#Actions
#Supply Chain Attacks
#Package Signing
#Defaults
#Waiting Periods
#Security
#Software Supply Chain
#Hacker News
#Author-side
#Controls
#Instrumentation
#Version Control
#Open Source
#Security Defaults
#Package Management
#Software Development
#CI/CD
#Vulnerability