Live Feed/GitHub/Fact Record
GitHub logo
GitHub
feature 96% Confidence Gate September 30, 2026

Opt-in dist-tag permissions for npm trusted publishing

GitHub has introduced an opt-in capability allowing npm trusted publishing configurations to manage dist-tags via OIDC credentials. This update enables automated workflows to promote versions to 'latest' or update 'next' and 'beta' pointers without static tokens.

Verified State Diff

Comparison Mode:
- Previous State
Trusted publishing via OIDC was limited to publishing package versions and required manual intervention or static tokens for managing dist-tags.
+ Verified New State
Trusted publishing configurations can now be explicitly granted permissions to manage dist-tags using short-lived OIDC credentials.

Impact & Verification Analysis

WHO IS AFFECTED

npm package maintainers and DevOps engineers utilizing GitHub Actions for automated package publishing.

WHY IT MATTERS

It improves security posture by removing the requirement for long-lived npm tokens and streamlines CI/CD pipelines by enabling fully automated version promotion and tag management.

Full Fact Overview

This feature extends the existing OIDC-based trusted publishing model for npm, which previously relied on short-lived credentials primarily for package publication. By granting OIDC identities permission to modify dist-tags, developers can now automate the lifecycle management of package releases—such as promoting a release candidate to production—entirely through GitHub Actions or other OIDC-compatible CI/CD providers. This eliminates the need to store long-lived npm access tokens as repository secrets, reducing the attack surface associated with credential leakage.

Multi-Source Evidence Chain (1)

Opt-in dist-tag permissions for npm trusted publishingGitHub
TRACKED ENTITY
Explore all historical GitHub changes
View GitHub Hub ➔