<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Software Supply Chain</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Software Supply Chain feed</description>
    <item>
      <title>GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing</title>
      <link>https://www.infoq.com/news/2026/08/github-npm-actions-defaults/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Software+Supply+Chain</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/08/github-npm-actions-defaults/en/headerimage/generatedHeaderImage-1785830307506.jpg"/&gt;&lt;p&gt;GitHub consolidated the npm and Actions changes it shipped from March to July 2026 against supply chain attacks, several of which alter defaults rather than add options. Hacker News discussion focused less on the individual controls than on whether waiting periods are the right instrument, or a substitute for author-side package signing.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Software Supply Chain</category>
      <category>Automation</category>
      <category>Open Source</category>
      <category>GitHub Actions</category>
      <category>github</category>
      <category>Continuous Delivery</category>
      <category>Security</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Sat, 08 Aug 2026 07:45:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/08/github-npm-actions-defaults/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Software+Supply+Chain</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-08-08T07:45:00Z</dc:date>
      <dc:identifier>/news/2026/08/github-npm-actions-defaults/en</dc:identifier>
    </item>
  </channel>
</rss>
