The OpenSSF statement is the clearest attempt yet to tell freeloaders the party's over. It doesn't advocate slamming the door ...
Hundreds of compromised packages pulled as registry shifts to 2FA and trusted publishing GitHub, which owns the npm registry ...