megachangelog
Security

Unvalidated npm trusted publishing configurations now expire

Unvalidated npm trusted publishing configurations now expire after 48 hours and can no longer authorize publishing, reducing the risk from repository or project name changes.

Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership.

Your configuration becomes validated and exempt from expiry after its first successful publish. Changing the repository or project identity requires a new trust relationship with a fresh 48-hour validation window—ordinary edits don’t restart the deadline.

If your configuration expires, recreate it to start a new 48-hour window. Expired configurations remain visible in trusted publisher settings but don’t count toward per-package limits. Other valid configurations on the package are unaffected.

npm also now rejects trusted publishing tokens from GitHub Actions issue_comment events, alongside the existing pull_request_target restriction. If affected, move publishing to a permitted event such as push, release, or workflow_dispatch.

Join the discussion within GitHub Community.

The post Unvalidated npm trusted publishing configurations now expire appeared first on The GitHub Blog.

npmsecuritypublishingtrusted-publishing

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →