Skip to content

🚀 Feature: Investigate using npm trusted publishing with OIDC #2270

@JoshuaKGoldberg

Description

@JoshuaKGoldberg

Feature Request Checklist

Overview

From https://github.blog/changelog/2025-07-31-npm-trusted-publishing-with-oidc-is-generally-available:

As of today, npm trusted publishing with OpenID Connect (OIDC) is now generally available. This feature enables you to securely publish npm packages directly from CI/CD workflows using OpenID Connect (OIDC) for authentication, reducing the need to manage long-lived tokens.

If this is the Current Recommended Thing for publishing, it'd be nice to look into it. Does it work well? Is it actually less work for repository maintainers? Can it be automated? Investigation required!

Additional Info

🎁

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions