npm Responds to Security Incident by Rotating Tokens and Pushing OIDC Publishing

RSync25 · x · 2026-08-05

Following a contained security incident, npm is rotating write-scoped Granular Access Tokens that bypass 2FA as a precaution. GitHub personal access tokens are unaffected.

Maintainers are advised to upgrade the npm CLI to v12+ and adopt Trusted Publishing. Using OIDC authentication, this feature allows publishing packages directly from CI/CD workflows without long-lived tokens. It currently supports GitHub Actions, GitLab CI/CD, and CircleCI.

Original post →

More from coding & agent

coding & agent channel →