Skip to content

npm publish-time malware scanning and dual-use metadata

UpdateVerifiedAdded Sep 22, 2026

As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time . This changelog covers what publishers can expect and a new metadata requirement for dual-use content.

Read GitHub's release notes

https://github.blog/changelog/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-metadata

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

Restricting npm bypass-2FA granular access tokens

Update

Customize code scanning default setup at scale

Update

Customize Dependabot pull request branch names

Update

Code coverage automatic enablement in Code Quality settings

Preview

CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support

Update

Also shipped on Jul 28, 2026

Snowflake Native Apps support for Virtual Private Snowflake on AWS for apps with containers (General availability)

VercelVercel platform

Vercel Connect now supports Custom Environments

Preview

Weekly: the week's data and AI releases, Tuesday mornings.