Skip to content

npm extends recovery-code security holds to all accounts

UpdateVerifiedAdded Sep 22, 2026

npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts. During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused.

Read GitHub's release notes

https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

CodeQL 2.27.0 adds support for Linux ARM64

Update

Block pull requests with exposed secrets from merging

Preview

Remediate Code Quality findings with agentic autofix

Update

AI Scan for pull request APIs in public preview

Preview

Enforce GitHub Advanced Security configurations

Update

Multiple trusted publishing configurations for npm

Also shipped on Sep 9, 2026

External secrets in Unity Catalog (Beta)

Beta
DatabricksLakeflow

Celigo connector (Beta)

Beta
DatabricksLakeflow

Anysphere Organization connector (Beta)

Beta
DatabricksLakeflow

Anaplan connector (Beta)

Beta

Openflow gen 1 deployment creation retired

Deprecation

Weekly: the week's data and AI releases, Tuesday mornings.