# GitHub is finally tightening up security around npm following multiple attacks

**URL:** https://discuss.privacyguides.net/t/github-is-finally-tightening-up-security-around-npm-following-multiple-attacks/31350
**Category:** News
**Tags:** article
**Created:** 2025-09-24T14:57:32Z
**Posts:** 1

## Post 1 by @KevPham — 2025-09-24T14:57:32Z

> **[GitHub is finally tightening up security around npm following multiple attacks](https://www.techradar.com/pro/security/github-is-finally-tightening-up-security-around-npm-following-multiple-attacks)**
>
> GitHub aims to harden package publication

> The announcement notes authentication and publishing options will be changed to include local publishing with required [2FA](https://www.techradar.com/best/best-authenticator-apps), granular tokens with a seven-day expiration date, and Trusted Publishing.
> 
> Furthermore, GitHub announced it would deprecate legacy classic tokens, as well as time-based one-time password (TOTP) 2FA, forcing users to migrate to FIDO-based 2FA. It will also limit granular tokens with publishing permissions to a shorter expiration, and set publishing access to disallow tokens by default (this should make users go for trusted publishers or 2FA enforced local publishing).
> 
> The option to bypass 2FA for local package publishing will be removed, while the list of eligible providers for trusted publishing will be expanded.
