Collaborating on code used to be hard. Then Git made branching and merging easy, and GitHub took care of the rest.
GitHub, which owns the npm registry for JavaScript packages, says it is tightening security in response to recent attacks.