No AI summary available for this article.
Why It Matters
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts.
Provenance
Discovered via GitHub and published by GitHub.
Key Claims
Original description
npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to… The post npm extends recovery-code security holds to all accounts appeared first on The GitHub Blog .
Discovered via GitHub
Repository releases, trending projects, and developer updates.
Publisher: github.blog
ID: https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts · Indexed about 2 hours ago