Skip to main content

Opt-in dist-tag permissions for npm trusted publishing

By Steven Van ·

Maintainers can now manage npm dist-tags from CI with short-lived OIDC credentials, once they enable the opt-in permission on a configuration.

npm trusted publishing configurations can now be allowed to manage dist-tags, such as promoting a version to latest or moving the next and beta pointers, using short-lived OIDC credentials. The permission is shown on GitHub's npm trusted publishing settings as Allow npm dist-tag.

Trusted publishing previously covered publishing and staging but not dist-tag operations. Maintainers who had otherwise moved to token-free workflows still had to keep a granular access token just to manage tags after a release or a rollback.

  • The permission is opt-in and defaults to off for both new and existing configurations, so no configuration gains new capability automatically.
  • It is independent of direct publishing, so a staging-only configuration can also be granted dist-tag management.
  • A dist-tag operation is authorized if the incoming OIDC token matches any one configuration that has the permission enabled.
  • Existing token-based dist-tag management continues to work unchanged.

To use it, open the package's trusted publishing settings and enable Allow npm dist-tag on the configurations that should be able to manage tags.

GitHub
GitHub
Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.
View GitHub →

Read the original announcement →

Read Opt-in dist-tag permissions for npm trusted publishing on Creators Toolbox