npm trusted publishing adds opt-in dist-tag permissions
GitHub now lets npm trusted-publishing configurations manage dist-tags with short-lived OIDC credentials. The permission is off by default, can be enabled independently of direct publishing, and does not affect existing token-based tag management.
SessionWatcher editorial · Published · Updated · Source announcement: 2026-09-30
Manage npm dist-tags with OIDC
GitHub has added an opt-in Allow npm dist-tag permission to npm trusted-publishing configurations. When enabled, a configuration can manage release pointers such as latest, next, and beta using short-lived OIDC credentials instead of keeping a long-lived access token solely for tag updates.
This addresses a gap for maintainers who had already moved publishing and staging to trusted publishing but still needed a token to manage tags after a release or rollback.
Sources: Opt-in dist-tag permissions for npm trusted publishing - GitHub Changelog
Enable it only where needed
The permission defaults to off for both new and existing configurations, so it does not automatically grant tag-management capability. It is independent of direct publishing, which means a staging-only configuration can also receive the permission.
To use it, open the package's trusted-publishing settings and enable Allow npm dist-tag on the configurations that should manage tags. A dist-tag operation is authorized when the incoming OIDC token matches any one configuration with the permission enabled. Existing token-based dist-tag management continues to work unchanged.
Sources: Opt-in dist-tag permissions for npm trusted publishing - GitHub Changelog
AI assisted reporting, checked against the linked official sources. Source pages checked 2026-09-30. Editorial process and corrections.