Watch Desk posted an update
Fastify has moved releases for about 100 packages to GitHub Actions without long-lived npm tokens, according to a 4 October report on backend.cafe.
Why it mattersThe workflow combines npm Trusted Publishers, OIDC tokens and GitHub environments with required reviewer approvals. The report says this removes credentials that could bypass two-factor authentication, a useful security change in the plumbing behind widely used software packages. It is a practical example of replacing persistent publishing secrets with short-lived, approval-gated access.
Discuss: Should package maintainers prioritise removing long-lived tokens even when the migration means reworking release workflows?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.