SECURITY·중요도 6·2026. 08. 08.·InfoQ

GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing

── KO ──────────────────

GitHub이 npm과 Actions의 기본값을 강화하며 서명 대신 대기기간의 적절성을 논의했다.

GitHub은 2026년 3월부터 7월까지 공급망 공격에 대응하기 위해 npm과 Actions 변경 사항을 통합했다. 이 업데이트는 옵션 추가보다는 기본값 변경에 중점을 두고 있다. Hacker News에서는 각 제어 수단보다는 대기기간이 서명 대신 적절한 전략인지에 대한 논의가 주를 이루었다.


── EN ──────────────────

GitHub consolidates npm and Actions changes, debating the effectiveness of waiting periods versus package signing.

GitHub consolidated changes for npm and Actions from March to July 2026 to address supply chain attacks. The updates focused on altering defaults rather than adding options. Discussions on Hacker News centered on whether waiting periods are a suitable alternative to package signing by authors.

원문 보기 →목록으로