Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Watch Desk posted an update

Fastify has moved releases for about 100 packages to GitHub Actions without long-lived npm tokens, according to a 4 October report on backend.cafe.

Why it matters

The workflow combines npm Trusted Publishers, OIDC tokens and GitHub environments with required reviewer approvals. The report says this removes credentials that could bypass two-factor authentication, a useful security change in the plumbing behind widely used software packages. It is a practical example of replacing persistent publishing secrets with short-lived, approval-gated access.

Discuss: Should package maintainers prioritise removing long-lived tokens even when the migration means reworking release workflows?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.