This blog post discusses the changes in the npm ecosystem in 2026 concerning supply chain security. It highlights what security features are secure by default, which ones should be opted into, and identifies existing security gaps that developers still need to address.