Pimp My IDE / garage dispatch
Back to garage
September 30, 2026 | npm / OIDC / release control

A tag can move without moving the package.

npm trusted publishing can now authorize dist-tag changes with short-lived OIDC credentials. That removes one long-lived token, but it also puts the release pointer inside automation.

Treat latest as a production pointer. Give its workflow a separate key, an exact version target, and a registry readback.

The package bytes and the release pointer are separate.

An npm distribution tag is an alias for one published package version. The default install command resolves latest. Teams often use next, beta, or canary for other release tracks. Moving a tag changes what many future installs receive without publishing new package bytes.[3]

That distinction makes a rollback fast. It also makes a small command consequential. npm dist-tag add package@2.1.0 latest can redirect the default install path to an existing version.

A release pointer deserves its own ignition key.

OIDC closes the leftover token gap.

npm trusted publishing exchanges a CI provider's OpenID Connect identity for a short-lived credential. The trust record binds the package to a named repository or project, workflow, and optional environment. The npm CLI uses that identity instead of a stored publish token.[2]

Until this update, maintainers could use OIDC to publish or stage a package but still needed a granular token to move dist-tags after a release or rollback. npm now exposes an independent Allow npm dist-tag permission. It is off by default. A staging-only workflow can receive tag permission without receiving direct publish permission.[1]

Short-lived credentials do not approve the target.

The credential answers who may ask. It does not prove that the requested version passed tests, contains the intended files, or belongs on latest. A safe job still needs an immutable package version, a protected trigger, a named tag, and a readback after the write.

The npm documentation also draws a hard boundary around trusted publishing. It supports publish, staged publish, and the documented dist-tag operations. It does not make npm whoami a permission test. Use the operation you intend to run. Self-hosted runners remain unsupported for trusted publishing at the time of writing.[2]

Read the pointer before and after the turn.

List current tags before changing one. Record the old version, requested version, workflow identity, registry, and command. Run the exact change. List tags again and compare the result. Keep the old version in the receipt so the rollback command is ready before the pointer moves.

The ignition lock below builds that receipt. It does not contact npm, inspect a package, or prove that a release is safe.

Interactive makeover / release pointer ignition

Turn the tag with both hands on the evidence

Traditional purpose replaced: a loose release command in CI. Better version: one native operation selector and four ordered evidence breakers drive a physical ignition, a visible pointer route, and a copyable change receipt.

Choose the pointer move

The selector chooses the command shape. The breakers choose which receipt sections to include. They do not mark real checks as passed.

Operation
Receipt sections
4 receipt sections openPromote latest
Pointer circuit / requested state

Dist-tag ignition lock

The operation is selected. The workflow identity is open.

Name the CI provider, repository or project, workflow file, and protected environment.

All four breakers means the receipt structure is ready. It does not mean a workflow matched, a permission exists, a version passed review, or the registry pointer moved.

One pointer / four records

Keep the release decision attached to the command.

01 / IDENTITY

Exact workflow

Record the CI provider, repository or project, workflow file, environment, and trigger that requested the change.

02 / AUTHORITY

Narrow permission

Grant dist-tag access independently. Do not add direct publish access when the workflow only moves a pointer.

03 / TARGET

Immutable version

Name the package, registry, version, tag, prior pointer, and review evidence before running the write.

04 / RESULT

Registry readback

List tags before and after the command. Save the exact rollback command beside the result.

Sources read

Source log and evidence boundary
  1. GitHub Changelog, "Opt-in dist-tag permissions for npm trusted publishing", published and read September 30, 2026. GitHub documents the new independent permission, its default-off state, OIDC authorization behavior, staging-only combinations, and continued support for token-based tag management.
  2. npm documentation, "Trusted publishing for npm packages", read September 30, 2026. npm documents provider and workflow binding, supported hosted CI providers, required CLI versions, independent allowed actions, automatic OIDC authentication, dist-tag limits, and the instruction to test the intended operation instead of relying on npm whoami.
  3. npm CLI documentation, npm dist-tag, read September 30, 2026. This primary source documents add, remove, and list operations, the default meaning of latest, prerelease tag conventions, and tag naming caveats.
  4. npm CLI documentation, "Registry", read September 30, 2026. This page documents registry selection, scope-based configuration, write APIs, and registry-specific authentication settings.

Evidence boundary: we read the release notice and current npm documentation. We did not change a package or run a dist-tag command because this run had no disposable npm package and no package-owner authorization. The interactive ignition builds a review template. It is not connected to npm and does not report production state.