Unvalidated npm trusted publishing configurations now expire
Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership.
Your configuration becomes validated and exempt from expiry after its first successful publish. Changing the repository or project identity requires a new trust relationship with a fresh 48-hour validation window—ordinary edits don’t restart the deadline.
If your configuration expires, recreate it to start a new 48-hour window. Expired configurations remain visible in trusted publisher settings but don’t count toward per-package limits. Other valid configurations on the package are unaffected.
npm also now rejects trusted publishing tokens from GitHub Actions issue_comment events, alongside the existing pull_request_target restriction. If affected, move publishing to a permitted event such as push, release, or workflow_dispatch.
Join the discussion within GitHub Community.