The npm blog has been discontinued. Updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. It’s been almost a year since npm acquired ^Lift Security and even less since the official formation of the internal npm Security Team. In addition to working on securing the Registry and its users, I’ve been setting aside time to think through how we look at security at npm