Disrupting supply chain attacks on npm and GitHub Actions
Summary
GitHub outlines security updates across npm and GitHub Actions aimed at disrupting supply chain attacks. The post details initial compromise techniques, credential exfiltration, and multiple hardening measures—such as read-only modes for high-impact accounts, safer defaults for Action workflows, and new credential revocation capabilities—to reduce attack surface and speed response.