Field Analysis
npm Staged Publishing Moves Package Security Toward Human-Gated Release
GitHub's staged publishing and new npm install-source controls give maintainers practical ways to slow compromised CI/CD paths before a malicious package becomes installable.
Read more:GitHub ChangelogCISA