Opt-in dist-tag permissions for npm trusted publishing
Summary
Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of… The post Opt-in dist-tag permissions for npm trusted publishing appeared first on The GitHub Blog .
Original Text
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd"> Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of a long-lived access token.
Previously, trusted publishing covered publishing and staging, but not dist-tag operations. That meant maintainers who had otherwise fully moved to token-free, OIDC-based workflows still had to keep a granular access token around solely to manage tags after a release or a rollback.
Each trusted publishing configuration now has an opt-in Allow npm dist-tag permission. It defaults to off for both new and existing configurations, so no configuration automatically gains new capability.
The permission is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
A dist-tag operation is authorized if the incoming OIDC token matches any one configuration with the permission enabled.
Existing token-based dist-tag management continues to work unchanged.
To use it, open your package’s trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.
Learn more about trusted publishers for npm.
Join the discussion within our roadmap discussions.
The post Opt-in dist-tag permissions for npm trusted publishing appeared first on The GitHub Blog.
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.