Restricting npm bypass-2FA granular access tokens
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of the largest credential-based attack surfaces on the registry. This only impacts npm granular access tokens.
Read GitHub's release noteshttps://github.blog/changelog/2026-07-31-restricting-npm-bypass-2fa-granular-access-tokens
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
CodeQL 2.26.1 improves analysis accuracy and framework coverage
UpdateSQLSecurityObservability
npm publish-time malware scanning and dual-use metadata
UpdateGovernanceSecurityObservability
Dependabot alerts on malicious packages across more ecosystems
UpdateSecurityData integration
Code coverage automatic enablement in Code Quality settings
PreviewAI agentsSecurityData integration
CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support
UpdateSQLGovernanceSecurity
Also shipped on Jul 31, 2026
[In preview] Public Preview: Azure SQL updates for late-July
PreviewSQLGovernanceDeveloper tools
DeepSeek V4 Flash now runs updated weights on AI Gateway
PreviewAI agentsPricingDeveloper tools
Expanded search for workflow runs in Vercel Observability
PreviewSQLObservabilityRegions