Remix.run Logo
GitHub introduces staged publishing and new install-time controls for NPM(github.blog)
34 points by brianmcnulty 10 hours ago | 3 comments
koinedad 3 hours ago | parent [-]

Nice…maybe will help some of the recent attacks

turkeyboi 2 hours ago | parent [-]

If maintainers actually use it

Klaster_1 2 hours ago | parent [-]

This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?