Opt-in dist-tag permissions for npm trusted publishing
By Steven Van ·
Maintainers can now manage npm dist-tags from CI with short-lived OIDC credentials, once they enable the opt-in permission on a configuration.
npm trusted publishing configurations can now be allowed to manage dist-tags, such as promoting a version to latest or moving the next and beta pointers, using short-lived OIDC credentials. The permission is shown on GitHub's npm trusted publishing settings as Allow npm dist-tag.
Trusted publishing previously covered publishing and staging but not dist-tag operations. Maintainers who had otherwise moved to token-free workflows still had to keep a granular access token just to manage tags after a release or a rollback.
- The permission is opt-in and defaults to off for both new and existing configurations, so no configuration gains new capability automatically.
- It is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
- A dist-tag operation is authorized if the incoming OIDC token matches any one configuration that has the permission enabled.
- Existing token-based dist-tag management continues to work unchanged.
To use it, open the package's trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.
