Opt-in dist-tag permissions for npm trusted publishing
Trusted publishing configurations for npm can now grant permission to manage dist-tags such as promoting versions to latest or updating next and beta pointers using short-lived OIDC credentials instead of permanent tokens.
Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of a long-lived access token.
Previously, trusted publishing covered publishing and staging, but not dist-tag operations. That meant maintainers who had otherwise fully moved to token-free, OIDC-based workflows still had to keep a granular access token around solely to manage tags after a release or a rollback.
- Each trusted publishing configuration now has an opt-in
Allow npm dist-tagpermission. It defaults to off for both new and existing configurations, so no configuration automatically gains new capability. - The permission is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
- A dist-tag operation is authorized if the incoming OIDC token matches any one configuration with the permission enabled.
- Existing token-based dist-tag management continues to work unchanged.
To use it, open your package’s trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.
Learn more about trusted publishers for npm.
Join the discussion within our roadmap discussions.
The post Opt-in dist-tag permissions for npm trusted publishing appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.