Home / Companies / Socket / Blog / Post Details
Content Deep Dive

npm Adopts OIDC for Trusted Publishing in CI/CD Workflows - ...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
759
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

npm has implemented Trusted Publishing with OpenID Connect (OIDC) to enhance the security of JavaScript package publishing in CI/CD workflows, eliminating the need for long-lived tokens and replacing them with short-lived, cryptographically-secured credentials. This move comes in response to recent supply chain attacks that exploited traditional token-based authentication, highlighting the need for more secure methods. By joining other platforms like PyPI, RubyGems, and crates.io in adopting trusted publishing based on OpenSSF recommendations, npm reduces the risk of credential compromise and ensures that packages are verified from specific CI systems, thereby mitigating the risk of token hijacking and malware injection. This new approach requires minimal setup, supports GitHub Actions and GitLab CI/CD initially, and plans to expand to more CI/CD providers, marking a significant step forward in JavaScript supply chain security and setting a new industry standard for package registries.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.