All AI updates

npm trusted publishing adds opt-in dist-tag permissions

GitHub now lets npm trusted-publishing configurations manage dist-tags with short-lived OIDC credentials. The permission is off by default, can be enabled independently of direct publishing, and does not affect existing token-based tag management.

SessionWatcher editorial · Published · Updated · Source announcement: 2026-09-30

Manage npm dist-tags with OIDC

GitHub has added an opt-in Allow npm dist-tag permission to npm trusted-publishing configurations. When enabled, a configuration can manage release pointers such as latest, next, and beta using short-lived OIDC credentials instead of keeping a long-lived access token solely for tag updates.

This addresses a gap for maintainers who had already moved publishing and staging to trusted publishing but still needed a token to manage tags after a release or rollback.

Sources: Opt-in dist-tag permissions for npm trusted publishing - GitHub Changelog

Enable it only where needed

The permission defaults to off for both new and existing configurations, so it does not automatically grant tag-management capability. It is independent of direct publishing, which means a staging-only configuration can also receive the permission.

To use it, open the package's trusted-publishing settings and enable Allow npm dist-tag on the configurations that should manage tags. A dist-tag operation is authorized when the incoming OIDC token matches any one configuration with the permission enabled. Existing token-based dist-tag management continues to work unchanged.

Sources: Opt-in dist-tag permissions for npm trusted publishing - GitHub Changelog

AI assisted reporting, checked against the linked official sources. Source pages checked 2026-09-30. Editorial process and corrections.