Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

The npm registry is deprecating TLS 1.0 and TLS 1.1

Blog post from GitHub

Post Details
Company
Date Published
Author
Edward Thomson
Word Count
353
Language
English
Hacker News Points
-
Summary

Starting October 4, 2021, all connections to npm websites and the npm registry must use TLS 1.2 or higher to enhance security, aligning with GitHub's commitment to service security and user privacy. Previously, GitHub removed support for TLS 1.0 and TLS 1.1, and now the same will be done for npmjs.com. While 99% of traffic to the npm registry already employs TLS 1.2, the transition is expected to minimally impact users. Most Node.js binary releases from v0.10.0 onwards support TLS 1.2, but users on unsupported versions or using custom-compiled binaries may need to upgrade. To prepare, notifications will be sent to users not using TLS 1.2, and TLS 1.2 will be enforced for specified hours on several dates leading up to the final enforcement. Users can verify their compatibility by installing a test package from an HTTPS endpoint.