npm extends recovery-code security holds to all accounts
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts. During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused.
Read GitHub's release noteshttps://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
GitHub Advanced Security expands trial availability
UpdateSecurityPricingObservability
Remediate Code Quality findings with agentic autofix
UpdateAI agentsGovernancePricing
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
Automatic Dependabot access to GitHub-hosted registries
UpdateDeveloper tools
Enforce GitHub Advanced Security configurations
UpdateGovernanceSecurityObservability