GitHub has announced the general availability of three major improvements to npm (Node Package Manager), aimed at making the software more secure and easier to use.
See also: NPM supply chain attack affects hundreds of websites

In summary, the new features include a more streamlined login and publishing experience, the ability to connect Twitter and GitHub accounts to npm, and a new package signature verification system
At the same time, GitHub announced that the two-factor authentication program introduced in May 2022 is ready to come out of beta and become available to all npm users.
The npm platform is a subsidiary of GitHub and is a package manager and repository for JavaScript, used by developer projects to download five billion packages daily.
It recently suffered large-scale security incidents that affected hundreds of applications and websites, forcing GitHub to urgently develop and implement a security hardening plan.
The new npm login and publishing system allows authentication to be handled by the web browser, so valid authentication tokens can be persisted in the same session for up to five minutes.
See also: SheetJS dropped support for npm registry
This change is intended to reduce the friction created by the introduction of the 2FA system, which forced developers to enter new one-time passwords with every action.

The new option to connect GitHub and Twitter accounts to npm aims to help add credibility and serve as a form of identity verification so that accounts can't impersonate the creators of popular software.
Additionally, this new system will help recover accounts when needed, making the process more reliable and less laborious and setting the stage for more automation in the future.
Finally, there is a new system that replaces the previous, complex, multi-step PGP process, allowing developers a much easier method to verify the signature of npm packages.
Users will now be able to validate the source of packages locally using the new “npm audit signatures” command in the npm CLI.
See also: GitHub: By the end of 2023 it will enforce 2FA on all code contributors
At the same time, the platform re-signs all packets with the ECDSA (elliptic curve cryptography) algorithm and uses HSM for key management, further enhancing security.
The next step for securing the npm registry is to enforce two-factor authentication on all accounts managing packages with more than one million weekly downloads or 500 dependencies.
Source: Bleeping Computer
