HomeinetGitHub introduces 2FA and quality of life improvements for npm

GitHub introduces 2FA and quality of life improvements for npm

GitHub has announced the general availability of three major improvements to npm (Node Package Manager), aimed at making the software more secure and easier to use.

See also: NPM supply chain attack affects hundreds of websites

GitHub

In summary, the new features include a more streamlined login and publishing experience, the ability to connect Twitter and GitHub accounts to npm, and a new package signature verification system

At the same time, GitHub announced that the two-factor authentication program introduced in May 2022 is ready to come out of beta and become available to all npm users.

The npm platform is a subsidiary of GitHub and is a package manager and repository for JavaScript, used by developer projects to download five billion packages daily.

It recently suffered large-scale security incidents that affected hundreds of applications and websites, forcing GitHub to urgently develop and implement a security hardening plan.

The new npm login and publishing system allows authentication to be handled by the web browser, so valid authentication tokens can be persisted in the same session for up to five minutes.

See also: SheetJS dropped support for npm registry

This change is intended to reduce the friction created by the introduction of the 2FA system, which forced developers to enter new one-time passwords with every action.

npm

The new option to connect GitHub and Twitter accounts to npm aims to help add credibility and serve as a form of identity verification so that accounts can't impersonate the creators of popular software.

Additionally, this new system will help recover accounts when needed, making the process more reliable and less laborious and setting the stage for more automation in the future.

Finally, there is a new system that replaces the previous, complex, multi-step PGP process, allowing developers a much easier method to verify the signature of npm packages.

Users will now be able to validate the source of packages locally using the new “npm audit signatures” command in the npm CLI.

See also: GitHub: By the end of 2023 it will enforce 2FA on all code contributors

At the same time, the platform re-signs all packets with the ECDSA (elliptic curve cryptography) algorithm and uses HSM for key management, further enhancing security.

The next step for securing the npm registry is to enforce two-factor authentication on all accounts managing packages with more than one million weekly downloads or 500 dependencies.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS