Opt-in dist-tag permissions for npm trusted publishing

Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of a long-lived access token.

Previously, trusted publishing covered publishing and staging, but not dist-tag operations. That meant maintainers who had otherwise fully moved to token-free, OIDC-based workflows still had to keep a granular access token around solely to manage tags after a release or a rollback.

  • Each trusted publishing configuration now has an opt-in Allow npm dist-tag permission. It defaults to off for both new and existing configurations, so no configuration automatically gains new capability.
  • The permission is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
  • A dist-tag operation is authorized if the incoming OIDC token matches any one configuration with the permission enabled.
  • Existing token-based dist-tag management continues to work unchanged.

To use it, open your package’s trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.

Learn more about trusted publishers for npm.

Join the discussion within our roadmap discussions.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论