Unvalidated npm trusted publishing configurations now expire

Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership.

Your configuration becomes validated and exempt from expiry after its first successful publish. Changing the repository or project identity requires a new trust relationship with a fresh 48-hour validation window—ordinary edits don’t restart the deadline.

If your configuration expires, recreate it to start a new 48-hour window. Expired configurations remain visible in trusted publisher settings but don’t count toward per-package limits. Other valid configurations on the package are unaffected.

npm also now rejects trusted publishing tokens from GitHub Actions issue_comment events, alongside the existing pull_request_target restriction. If affected, move publishing to a permitted event such as push, release, or workflow_dispatch.

Join the discussion within GitHub Community.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论