Disrupting supply chain attacks on npm and GitHub Actions

We have implemented critical security updates across npm and GitHub Actions to stop supply chain attacks. These changes include preventive account protection, safer workflow defaults, and staged publishing to block malware distribution. By removing long-lived credentials and adding network firewalls, we are cutting off common attack paths to protect the open source ecosystem.
Supply chain attacks chain together several weaknesses, and there is no single security capability that can stop them.