
npm has implemented a 48-hour expiration for unvalidated trusted publishing configurations to mitigate supply chain risks associated with repository ownership changes. Configurations become permanent only after their first successful publish; subsequent changes to project identity require re-validation. The update also blocks trusted publishing tokens from GitHub Actions issue_comment events, restricting valid triggers to push, release, or workflow_dispatch. Expired configurations remain visible but do not count toward package limits.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
GitHub Changelog · June 25, 2026 · Related
GitHub Changelog · September 3, 2026 · Same story
© GitHub ChangelogGitHub quietly expanded its secret scanning partnership program to include Lovable Labs, Pydantic Services, and Supabase. This update means credentials from these popular development platforms are now automatically detected in public repositories, allowing the providers to revoke or rotate compromised keys before abuse occurs. For developers using Supabase or Lovable, this adds a critical layer of automated security hygiene without requiring manual configuration. It reflects GitHub's ongoing effort to integrate directly with the modern AI and database tooling stack that dominates current development workflows.
© GitHub ChangelogGitHub finally exposes Copilot code review to external automation via REST and GraphQL APIs, moving it from a manual UI action to an integrable pipeline step. This allows developers to trigger reviews directly from scripts or internal tools rather than relying on the web interface. Simultaneously, the default effort level shifts to Balanced, striking a middle ground between speed and depth for most repositories. While Lite remains available for those prioritizing raw throughput, the API access is the real win here, enabling true CI/CD integration for automated code quality checks.
© GitHub Changelognpm has closed a major gap in its staged publishing workflow by allowing the creation of entirely new packages directly from the staging queue. Previously, developers had to perform an initial public publish before they could leverage the safety net of staged releases for subsequent versions. This update enables automated workflows to initialize scoped and unscoped packages securely using granular access tokens, ensuring that the very first version also undergoes maintainer review before becoming installable. It effectively removes the manual friction from setting up secure, review-gated package lifecycles.
Healthcare remains the final frontier for voice AI, and Vocca’s $20 million raise signals serious capital flowing into automating high-stakes phone interactions. Unlike generic assistants, this funding targets the messy reality of patient scheduling and triage, where accuracy and empathy are non-negotiable. It marks a shift from experimental chatbots to deployed voice agents handling critical administrative workflows. The market is watching to see if specialized vertical models can outperform generalist APIs in regulated environments.
Hadrian has secured $40 million to defend against the rising tide of AI-powered cyberattacks. This funding signals a critical pivot in cybersecurity: as attackers leverage generative models to craft sophisticated phishing and malware, defenders must adopt equally advanced AI tools to keep pace. The investment validates the urgent need for automated, intelligent threat detection systems that can operate at machine speed. For security teams, this means the era of manual rule-based defense is ending, replaced by adaptive AI counters.
© The Verge AIOpenAI’s aggressive push into mathematics has triggered a severe reputational crisis within the academic community. After claiming solutions to major problems like Navier-Stokes using massive agent swarms, researchers accused the lab of unethical data practices and scooping peers. The company’s response—a new advisory panel—has been met with skepticism rather than relief. This exposes a fundamental clash between Silicon Valley’s speed-first culture and academia’s norms of transparency and collaboration. The real story isn't just the math; it's the institutional friction caused by AI labs treating research as a race. KleidiAI on Apple Silicon now compiles in default, meaning every M-series machine gets ARM-tuned GEMM kernels for free. ROCm 7.2 added as a default build narrows the AMD/CUDA gap visibly. There's no new model and no new quantization here — just llama.cpp quietly becoming the inference runtime for everyone who isn't on NVIDIA.