Your CI/CD pipeline may already be able to publish an npm package.
But here’s the more important question:
Should every workflow that can publish also be allowed to change latest, next, or beta tags?
GitHub’s recent npm trusted publishing update makes this separation much clearer.
Workflows can now receive explicit permission to manage npm distribution tags using short-lived OIDC credentials instead of keeping long-lived automation tokens around.
Why this matters
Release tags can directly affect which version users install.
Changing:
latest
next
beta
may look like a small metadata change, but in practice it can influence production adoption, prerelease testing, and package distribution.
That means tag management deserves its own permission boundary.
What development teams should review
Before changing anything in production, I’d check these first:
- Which workflow actually needs to manage release tags?
- Does that workflow really need broader publishing permissions too?
- Can the operation be handled through OIDC-based trusted publishing?
- Have you tested tag updates before removing existing credentials?
- Are old automation tokens still required anywhere else?
A good principle here is:
Give automation only the permissions it actually needs.
The tag-management permission is off by default, which is a sensible security choice.
And importantly, moving to short-lived credentials does not remove the need for:
- release testing
- permission reviews
- CI/CD controls
- rollback planning
- software supply-chain security
Discussion
I think this is a good example of where least privilege becomes practical, not theoretical.
Publishing a package and deciding which release becomes latest are related actions—but they are not necessarily the same responsibility.
How are you handling this in your npm workflows today?
Do you keep publishing and tag management in one workflow, or would you separate them?
#NPM #GitHubActions #DevSecOps #CICD #OIDC #SoftwareEngineering #DevOps #SoftwareSupplyChain #PackageManagement #OpenSource #DeveloperTools #Automation #NodeJS #WaqasAhmad