Who Can Change Your npm Release Tags?

Who Can Change Your npm Release Tags?

●2 ●11 ●45
calendar_today ago • schedule1 min read

Who Should Be Allowed to Change Your npm Release Tags?

Your CI/CD pipeline may already be able to publish an npm package.

But here’s the more important question:

Should every workflow that can publish also be allowed to change latest, next, or beta tags?

GitHub’s recent npm trusted publishing update makes this separation much clearer.

Workflows can now receive explicit permission to manage npm distribution tags using short-lived OIDC credentials instead of keeping long-lived automation tokens around.

Why this matters

Release tags can directly affect which version users install.

Changing:

latest
next
beta

may look like a small metadata change, but in practice it can influence production adoption, prerelease testing, and package distribution.

That means tag management deserves its own permission boundary.

What development teams should review

Before changing anything in production, I’d check these first:

  • Which workflow actually needs to manage release tags?
  • Does that workflow really need broader publishing permissions too?
  • Can the operation be handled through OIDC-based trusted publishing?
  • Have you tested tag updates before removing existing credentials?
  • Are old automation tokens still required anywhere else?

A good principle here is:

Give automation only the permissions it actually needs.

The tag-management permission is off by default, which is a sensible security choice.

And importantly, moving to short-lived credentials does not remove the need for:

  • release testing
  • permission reviews
  • CI/CD controls
  • rollback planning
  • software supply-chain security

Discussion

I think this is a good example of where least privilege becomes practical, not theoretical.

Publishing a package and deciding which release becomes latest are related actions—but they are not necessarily the same responsibility.

How are you handling this in your npm workflows today?

Do you keep publishing and tag management in one workflow, or would you separate them?

#NPM #GitHubActions #DevSecOps #CICD #OIDC #SoftwareEngineering #DevOps #SoftwareSupplyChain #PackageManagement #OpenSource #DeveloperTools #Automation #NodeJS #WaqasAhmad

Part 5 of 5 in Discussions BOARD

4 Comments

1 vote
0
2 votes
1
🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Local-First: The Browser as the Vault

Pocket Portfolio - Apr 20

Your AI Doesn't Just Write Tests. It Runs Them Too.

Kevin Martinez - May 12

Split-Brain: Analyst-Grade Reasoning Without Raw Transactions on the Server

Pocket Portfolio - Apr 8

Setting GitHub as a trusted publisher for npm

Steve Fentonverified - May 26

The Trust Gap: Why Your Product Fails Even When the Math is Right

Karol Modelski - Jul 16
chevron_left
1.5k Points • 58 Badges
Faisal Town Lahore B Block • dotera.co
20Posts
17Comments
16Connections
Waqas Ahmad is a Content Creator and Software Engineer passionate about building brands through cont... Show more

Related Jobs

View all jobs →

Commenters (This Week)

2 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!