Staged publishing and new install-time controls for npm

39 pointsposted 11 hours ago
by brianmcnulty

3 Comments

koinedad

5 hours ago

Nice…maybe will help some of the recent attacks

turkeyboi

3 hours ago

If maintainers actually use it

Klaster_1

3 hours ago

This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?