
npm has updated its staged publishing feature to support the creation of new packages, not just updates to existing ones. Users can now initialize public scoped, unscoped, and private scoped packages directly within the staging workflow using local sessions or granular access tokens, including stage-only tokens. The first version of a newly created package enters the staged queue, requiring explicit promotion by a maintainer before it becomes available for installation. This change allows developers to configure trusted publishing and manage settings immediately after creation without needing an initial public release.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
GitHub Changelog · September 3, 2026 · Same story
GitHub Changelog · September 18, 2026 · Related
© GitHub ChangelogGitHub quietly expanded its secret scanning partnership program to include Lovable Labs, Pydantic Services, and Supabase. This update means credentials from these popular development platforms are now automatically detected in public repositories, allowing the providers to revoke or rotate compromised keys before abuse occurs. For developers using Supabase or Lovable, this adds a critical layer of automated security hygiene without requiring manual configuration. It reflects GitHub's ongoing effort to integrate directly with the modern AI and database tooling stack that dominates current development workflows.
© GitHub ChangelogGitHub finally exposes Copilot code review to external automation via REST and GraphQL APIs, moving it from a manual UI action to an integrable pipeline step. This allows developers to trigger reviews directly from scripts or internal tools rather than relying on the web interface. Simultaneously, the default effort level shifts to Balanced, striking a middle ground between speed and depth for most repositories. While Lite remains available for those prioritizing raw throughput, the API access is the real win here, enabling true CI/CD integration for automated code quality checks.
© GitHub Changelognpm is tightening security on its trusted publishing feature by imposing a strict 48-hour expiration window for unvalidated configurations. This change directly targets supply chain risks where repository ownership changes could hijack trust relationships before they are fully vetted. Once a configuration successfully publishes, it becomes permanent, but any shift in project identity forces a fresh validation cycle. Additionally, tokens from GitHub Actions issue_comment events are now blocked, pushing developers toward safer triggers like push or release. This is a necessary hardening of the npm ecosystem that prioritizes security over convenience.
This release significantly tightens the security model for Claude Code plugins by exposing server tool IDs and approval ceilings to hook functions, allowing developers to build more granular permission checks. It also stabilizes long-running agent sessions by fixing critical bugs in subagent resume logic and scheduled task persistence after compaction. For plugin authors, the new validation flags ensure gating hooks are properly configured before deployment. These changes make the platform safer for enterprise use while reducing friction for complex automated workflows.
This release quietly closes the hardware gap for local inference by adding default support for CUDA 13 and ROCm 10.0 alongside existing CUDA 12 builds. NVIDIA users can now leverage newer driver stacks without manual configuration, while AMD GPU owners finally get first-class parity with the same ease of use previously reserved for CUDA. Apple Silicon KleidiAI is disabled in this specific build, a notable regression for Mac users who rely on that optimization. The inclusion of Snapdragon and OpenVINO binaries further broadens the reach to edge devices and Intel hardware. It’s less about new features and more about llama.cpp solidifying its position as the universal runtime for every major accelerator.
This release quietly cements llama.cpp as the universal inference runtime by finally bringing first-class ROCm 10.0 support to both Linux and Windows. AMD GPU users no longer need workarounds, effectively closing a long-standing parity gap with NVIDIA's CUDA ecosystem. The inclusion of Snapdragon AI stack binaries for Linux marks a strategic push into ARM-based edge devices, while the simultaneous addition of CUDA 13 builds ensures compatibility with the latest driver stacks. By standardizing these hardware backends across major operating systems, the project removes friction for developers deploying models on diverse non-NVIDIA hardware.