Stage-only npm tokens for safer automation
You can now select Read and write (stage only) when creating an npm granular access token. This lets your automated workflows stage package versions for review without giving the token permission to publish new versions directly to the npm registry. Your workflow uses npm stage publish to submit a version.
Read GitHub's release noteshttps://github.blog/changelog/2026-09-18-stage-only-npm-tokens-for-safer-automation
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Manage the code coverage ruleset condition with the REST API
GAObservabilityDeveloper tools
Code scanning AI Scan no longer requires CodeQL default setup
PreviewSecurityObservability
GitHub Enterprise adds credential inventory exports
UpdateSecurityPricingObservability
Enforce GitHub Advanced Security configurations
UpdateGovernanceSecurityObservability
Deprecation notice: All-platform CodeQL bundle
DeprecationObservabilityDeveloper tools
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
npm extends recovery-code security holds to all accounts
UpdateSecurityObservability
Also shipped on Sep 18, 2026
Databricks Apps telemetry is now generally available
GAGovernanceObservabilityDeveloper tools
Agent Platform SDK for Python version 2.0.1 is available
DeprecationAI agentsDeveloper tools