16 × AIAI signal, amplified
AI newsTopicsAboutSources
TelegramFollow on Telegram
AI newsTopicsAboutSources
16 × AIAI signal, amplified

An AI news engine that ingests trusted sources, scores with Claude, and posts only what clears the bar.

Follow on Telegram →

Subscribe

  • Telegram
  • RSS
  • All channels

Newsletter

Used only to send this newsletter. Privacy

Legal

  • Privacy
  • Imprint
© 2026 16 × AI. All rights reserved.A new issue every two days.
Home/Market & Regulation
Market & Regulation

npm trusted publishing configs expire in 48 hours

GitHub Changelog·October 2, 2026·high confidence

Why it matters

  • →Unvalidated npm trusted publishing configs now expire after 48 hours to prevent ownership hijacking.
  • →Tokens from GitHub Actions issue_comment events are rejected, forcing use of safer triggers like push.
  • →Permanent trust is only granted after the first successful publish event.
npm trusted publishing configs expire in 48 hours
©GitHub Changelog

npm has implemented a 48-hour expiration for unvalidated trusted publishing configurations to mitigate supply chain risks associated with repository ownership changes. Configurations become permanent only after their first successful publish; subsequent changes to project identity require re-validation. The update also blocks trusted publishing tokens from GitHub Actions issue_comment events, restricting valid triggers to push, release, or workflow_dispatch. Expired configurations remain visible but do not count toward package limits.

Read original

The story around this

Earlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.

npm Enhances Security for High-Impact Accounts — GitHub Changelog1npm Enhances Trusted Publishing Configurations — GitHub Changelog2npm trusted publishing configs expire in 48 hoursJun 25You are here

How we got here

  1. 1
    npm Enhances Security for High-Impact Accounts

    GitHub Changelog · June 25, 2026 · Related

  2. 2
    npm Enhances Trusted Publishing Configurations

    GitHub Changelog · September 3, 2026 · Same story

More from GitHub Changelog

GitHub Secret Scanning adds Lovable and Supabase detectors© GitHub Changelog
Coding Toolscoding

GitHub Secret Scanning adds Lovable and Supabase detectors

GitHub quietly expanded its secret scanning partnership program to include Lovable Labs, Pydantic Services, and Supabase. This update means credentials from these popular development platforms are now automatically detected in public repositories, allowing the providers to revoke or rotate compromised keys before abuse occurs. For developers using Supabase or Lovable, this adds a critical layer of automated security hygiene without requiring manual configuration. It reflects GitHub's ongoing effort to integrate directly with the modern AI and database tooling stack that dominates current development workflows.

GitHub Changelog·Oct 5, 2026
GitHub Copilot Code Review API and Default Effort Change© GitHub Changelog
Coding Toolscoding

GitHub Copilot Code Review API and Default Effort Change

GitHub finally exposes Copilot code review to external automation via REST and GraphQL APIs, moving it from a manual UI action to an integrable pipeline step. This allows developers to trigger reviews directly from scripts or internal tools rather than relying on the web interface. Simultaneously, the default effort level shifts to Balanced, striking a middle ground between speed and depth for most repositories. While Lite remains available for those prioritizing raw throughput, the API access is the real win here, enabling true CI/CD integration for automated code quality checks.

GitHub Changelog·Oct 2, 2026
npm staged publishing now supports new package creation© GitHub Changelog
Coding Toolscoding

npm staged publishing now supports new package creation

npm has closed a major gap in its staged publishing workflow by allowing the creation of entirely new packages directly from the staging queue. Previously, developers had to perform an initial public publish before they could leverage the safety net of staged releases for subsequent versions. This update enables automated workflows to initialize scoped and unscoped packages securely using granular access tokens, ensuring that the very first version also undergoes maintainer review before becoming installable. It effectively removes the manual friction from setting up secure, review-gated package lifecycles.

GitHub Changelog·Oct 2, 2026

More in Market & Regulation

Investment · $20m
Market & Regulationbusiness

Vocca raises $20m for patient call automation

Healthcare remains the final frontier for voice AI, and Vocca’s $20 million raise signals serious capital flowing into automating high-stakes phone interactions. Unlike generic assistants, this funding targets the messy reality of patient scheduling and triage, where accuracy and empathy are non-negotiable. It marks a shift from experimental chatbots to deployed voice agents handling critical administrative workflows. The market is watching to see if specialized vertical models can outperform generalist APIs in regulated environments.

Sifted·Oct 6, 2026
Investment · $40m
Market & Regulationother

Hadrian raises $40m for AI security

Hadrian has secured $40 million to defend against the rising tide of AI-powered cyberattacks. This funding signals a critical pivot in cybersecurity: as attackers leverage generative models to craft sophisticated phishing and malware, defenders must adopt equally advanced AI tools to keep pace. The investment validates the urgent need for automated, intelligent threat detection systems that can operate at machine speed. For security teams, this means the era of manual rule-based defense is ending, replaced by adaptive AI counters.

Sifted·Oct 6, 2026
OpenAI faces backlash over math breakthroughs and ethics© The Verge AI
Market & Regulationother

OpenAI faces backlash over math breakthroughs and ethics

OpenAI’s aggressive push into mathematics has triggered a severe reputational crisis within the academic community. After claiming solutions to major problems like Navier-Stokes using massive agent swarms, researchers accused the lab of unethical data practices and scooping peers. The company’s response—a new advisory panel—has been met with skepticism rather than relief. This exposes a fundamental clash between Silicon Valley’s speed-first culture and academia’s norms of transparency and collaboration. The real story isn't just the math; it's the institutional friction caused by AI labs treating research as a race. KleidiAI on Apple Silicon now compiles in default, meaning every M-series machine gets ARM-tuned GEMM kernels for free. ROCm 7.2 added as a default build narrows the AMD/CUDA gap visibly. There's no new model and no new quantization here — just llama.cpp quietly becoming the inference runtime for everyone who isn't on NVIDIA.

The Verge AI·Oct 5, 2026