Multiple trusted publishing configurations for npm
We’re continuing to make trusted publishing smoother for npm publishers, guided by maintainers feedback. Three updates to npm publishing are now generally available: Multiple trusted publishing configurations per package Staged packages can only be approved after malware scanning is complete Maintainers can see their staged history in the package versions...
Read GitHub's release noteshttps://github.blog/changelog/2026-09-03-multiple-trusted-publishing-configurations-for-npm
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Automatic Dependabot access to GitHub-hosted registries
UpdateDeveloper tools
npm extends recovery-code security holds to all accounts
UpdateSecurityObservability
GitHub Advanced Security expands trial availability
UpdateSecurityPricingObservability
Remediate Code Quality findings with agentic autofix
UpdateAI agentsGovernancePricing
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
Block users directly from security advisories
UpdateStreamingSecurityObservability