Opt-in dist-tag permissions for npm trusted publishing
GitHub has introduced an opt-in capability allowing npm trusted publishing configurations to manage dist-tags via OIDC credentials. This update enables automated workflows to promote versions to 'latest' or update 'next' and 'beta' pointers without static tokens.
Verified State Diff
Impact & Verification Analysis
npm package maintainers and DevOps engineers utilizing GitHub Actions for automated package publishing.
It improves security posture by removing the requirement for long-lived npm tokens and streamlines CI/CD pipelines by enabling fully automated version promotion and tag management.
Full Fact Overview
This feature extends the existing OIDC-based trusted publishing model for npm, which previously relied on short-lived credentials primarily for package publication. By granting OIDC identities permission to modify dist-tags, developers can now automate the lifecycle management of package releases—such as promoting a release candidate to production—entirely through GitHub Actions or other OIDC-compatible CI/CD providers. This eliminates the need to store long-lived npm access tokens as repository secrets, reducing the attack surface associated with credential leakage.