product1 publisher
npm keeps accepting write tokens after you switch on OIDC trusted publishing
Trusted publishing swaps a stored npm token for a short-lived OIDC one, and it needs npm CLI 11.5.1, Node 22.14.0 and a hosted runner. The CLI falls back to the old token whenever the OIDC path is absent.
Publishers:docs.npmjs.com
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives78
- Confidence62