npm Responds to Security Incident by Rotating Tokens and Pushing OIDC Publishing
RSync25 · x · 2026-08-05
Following a contained security incident, npm is rotating write-scoped Granular Access Tokens that bypass 2FA as a precaution. GitHub personal access tokens are unaffected.
Maintainers are advised to upgrade the npm CLI to v12+ and adopt Trusted Publishing. Using OIDC authentication, this feature allows publishing packages directly from CI/CD workflows without long-lived tokens. It currently supports GitHub Actions, GitLab CI/CD, and CircleCI.
More from coding & agent
- Garage Solar-Powered 384GB Xeon Rig for Remote AI Coding — angadsg · 2026-08-05
- McKinsey Survey Reveals AI Adoption Truth: Workflow Redesign Beats Readiness Talk — sanjaykalra · 2026-08-05
- Dev Struggles to Dynamically Inject AGENTS.md in Junior Coding Agent — zeeg · 2026-08-05
- Open-Sourced Recipe: Running a 27B Local Agent 24/7 on a Single RTX 5090 — max_paperclips · 2026-08-05
- Open-source multi-model orchestrator fable-advisor uses Opus as architect — daniel_mac8 · 2026-08-05
- Dev Open-Sources Visual Frontend for OpenEvolve Focused on Adversarial Workflows — jazir55 · 2026-08-05