GitHub's plan for a more secure NPM supply chain(github.blog) |
GitHub's plan for a more secure NPM supply chain(github.blog) |
They still need it still needs a Personal Access Tokens - but many organisations restrict them now, and even bypassing that, the PAT tokens are too broad in there permissions (github cli being one example)