Home / Companies / Speakeasy / Blog / Post Details
Content Deep Dive

Securing Your NPM Publishing: Transitioning to Trusted Publishing

Blog post from Speakeasy

Post Details
Company
Date Published
Author
Speakeasy Team
Word Count
603
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

In response to recent supply chain attacks, the npm ecosystem has implemented significant security changes, particularly concerning authentication tokens. Starting in October, newly created write-enabled granular access tokens will expire after seven days by default, with a maximum lifespan of 90 days. Additionally, npm will revoke all existing legacy tokens and disable their future generation. To enhance security and simplify the publishing process, transitioning to Trusted Publishing using OpenID Connect (OIDC) is recommended, as it eliminates token rotation and provides automatic provenance attestation. The process involves updating GitHub workflow permissions and configuring trusted publishing settings on npm, which, despite requiring initial setup, promises long-term benefits in terms of security and maintenance.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 1 3,335 319 128 -31%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.