Skip to content

Conversation

@direnakkoc
Copy link
Collaborator

@direnakkoc direnakkoc commented Jan 21, 2026

npm announced the following security change:
Security Notice: Classic tokens have been revoked. Granular tokens are now limited to 90 days and require 2FA by default. Update your CI/CD workflows to avoid disruption.
To align with this update and prevent CI/CD disruptions, we have upgraded the release workflow to use npm Trusted Publishing (OIDC) instead of token-based authentication.

This removes the need for long-lived npm tokens and ensures the publishing process complies with npm’s latest security requirements.

Example configuration on the npm side is included below for reference.
Screenshot 2026-01-22 at 10 59 18
Example configuration on npm side:
Screenshot 2026-01-22 at 11 02 12

Successful release run: https://github.com/fourTheorem/slic-watch/actions/runs/21244408980/job/61129937699

@coveralls
Copy link

coveralls commented Jan 21, 2026

Coverage Status

coverage: 97.662%. remained the same
when pulling b7faf68 on chore/investigate-build-error
into c831e6f on main.

@direnakkoc direnakkoc requested a review from eoinsha January 22, 2026 11:06
@direnakkoc direnakkoc merged commit cebb06d into main Jan 22, 2026
6 checks passed
@eoinsha eoinsha deleted the chore/investigate-build-error branch January 22, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants