npm Supply Chain Security Upgrades: Publish-Time Malware Scanning and Dual-Use Metadata
GitHub published npm publish-time malware scanning and dual-use metadata detection, while strengthening Dependabot and Actions protections. Software supply chain security is shifting from post-install cleanup to pre-publish blocking.