The package bytes and the release pointer are separate.
An npm distribution tag is an alias for one published package version. The default install command resolves latest. Teams often use next, beta, or canary for other release tracks. Moving a tag changes what many future installs receive without publishing new package bytes.[3]
That distinction makes a rollback fast. It also makes a small command consequential. npm dist-tag add package@2.1.0 latest can redirect the default install path to an existing version.
A release pointer deserves its own ignition key.
OIDC closes the leftover token gap.
npm trusted publishing exchanges a CI provider's OpenID Connect identity for a short-lived credential. The trust record binds the package to a named repository or project, workflow, and optional environment. The npm CLI uses that identity instead of a stored publish token.[2]
Until this update, maintainers could use OIDC to publish or stage a package but still needed a granular token to move dist-tags after a release or rollback. npm now exposes an independent Allow npm dist-tag permission. It is off by default. A staging-only workflow can receive tag permission without receiving direct publish permission.[1]
Short-lived credentials do not approve the target.
The credential answers who may ask. It does not prove that the requested version passed tests, contains the intended files, or belongs on latest. A safe job still needs an immutable package version, a protected trigger, a named tag, and a readback after the write.
The npm documentation also draws a hard boundary around trusted publishing. It supports publish, staged publish, and the documented dist-tag operations. It does not make npm whoami a permission test. Use the operation you intend to run. Self-hosted runners remain unsupported for trusted publishing at the time of writing.[2]
Read the pointer before and after the turn.
List current tags before changing one. Record the old version, requested version, workflow identity, registry, and command. Run the exact change. List tags again and compare the result. Keep the old version in the receipt so the rollback command is ready before the pointer moves.
The ignition lock below builds that receipt. It does not contact npm, inspect a package, or prove that a release is safe.