> New TOTP (Time-based One-Time Password) setups for npm access will be permanently disabled. Existing TOTP configurations will continue to work for now, but they will be phased out in the coming months.
no, i zaraz tylko zintegrują webauthn z dowodami cyfrowymi i nie będzie można publikować pakietów w npmjs bez potwierdzenia tożsamości.
Przegapiłem też że #npmjs to teraz gith..., eee, micro$oft
Strengthening npm security: Important changes to authentication and token management - GitHub Changelog
As part of our ongoing commitment to securing the npm ecosystem, we’re implementing the first phase of security improvements outlined in our recent announcement. These changes will roll out over…