Opt-in dist-tag permissions for npm trusted publishing
Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of a long-lived access token.
Previously, trusted publishing covered publishing and staging, but not dist-tag operations. That meant maintainers who had otherwise fully moved to token-free, OIDC-based workflows still had to keep a granular access token around solely to manage tags after a release or a rollback.
- Each trusted publishing configuration now has an opt-in
Allow npm dist-tagpermission. It defaults to off for both new and existing configurations, so no configuration automatically gains new capability. - The permission is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
- A dist-tag operation is authorized if the incoming OIDC token matches any one configuration with the permission enabled.
- Existing token-based dist-tag management continues to work unchanged.
To use it, open your package’s trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.
Learn more about trusted publishers for npm.
Join the discussion within our roadmap discussions.