megachangelog
Feature

Opt-in dist-tag permissions for npm trusted publishing

Trusted publishing configurations for npm can now grant permission to manage dist-tags such as promoting versions to latest or updating next and beta pointers using short-lived OIDC credentials instead of permanent tokens.

Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of a long-lived access token.

Previously, trusted publishing covered publishing and staging, but not dist-tag operations. That meant maintainers who had otherwise fully moved to token-free, OIDC-based workflows still had to keep a granular access token around solely to manage tags after a release or a rollback.

  • Each trusted publishing configuration now has an opt-in Allow npm dist-tag permission. It defaults to off for both new and existing configurations, so no configuration automatically gains new capability.
  • The permission is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
  • A dist-tag operation is authorized if the incoming OIDC token matches any one configuration with the permission enabled.
  • Existing token-based dist-tag management continues to work unchanged.

To use it, open your package’s trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.

Learn more about trusted publishers for npm.

Join the discussion within our roadmap discussions.

The post Opt-in dist-tag permissions for npm trusted publishing appeared first on The GitHub Blog.

npmtrusted-publishingoidcsecuritypackage-management

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →