github: npm publish-time malware scanning and dual-use metadata
npm is adding automatic malware scanning when packages are published, along with a new metadata requirement for packages that may be used for both benign and malicious purposes. The changelog says this is part of ongoing supply-chain security work and explains what publishers should expect.