• Sources: GitHub changelog, HN 49092172
  • Summary: A GitHub changelog entry dated 2026-07-28 states that npm now scans every package at publish time and adds a dual-use content declaration. The scan puts a delay between the publish call and the version becoming installable, described as typically around five minutes and longer at peak times or depending on package content and size, up to 15 minutes or more, with GitHub stating those figures are not a service guarantee. A package with security-relevant capability is expected to carry a contentPolicy field, a DISCLOSURE file, and 2FA-enforced publishing to avoid being blocked by default. GitHub states the requirement will be progressively enforced over time and that it is emailing affected maintainers, so the block is not yet universal.
  • Why it matters: Any release pipeline that publishes to npm and then immediately installs the published version now has a timing window it did not have before, and security tooling shipped as npm packages has a metadata requirement attached to staying installable as enforcement widens.
  • Follow-up: Watch for the enforcement date on the dual-use declaration, and for false positives blocking legitimate security tooling.

send feedback on this story