istanbuljs / istanbuljs/test-exclude

Consider adopting npm trusted publishing

Open
#66 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
10
Forks
18
PR merge metrics
No merged PRs in 30d

Description

Recent [supply chain attacks on npm](https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/) have highlighted the need for stronger package publishing security. The September 2025 Shai-Hulud worm compromised 500+ packages through stolen maintainer tokens, showing the risks of token-based publishing.

Trusted publishing helps by eliminating long-lived tokens that can be stolen or accidentally exposed; generating automatic provenance provides cryptographic proof of where/how packages are built; and is an industry standard adopted by PyPI, RubyGems, crates.io, NuGet, etc.

Here's the short version:

1. [Configure a trusted publisher on npmjs.com](https://docs.npmjs.com/trusted-publishers#github-actions-configuration)
1. Add `id-token: write` permission to your workflow
1. Remove `NODE_AUTH_TOKEN` from your workflow

npm is [planning to deprecate legacy tokens](https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/#h-npm-s-roadmap-for-hardening-package-publication) and make trusted publishing the preferred method.

Would you consider adopting trusted publishing to help secure the npm ecosystem?

References:

- [npm trusted publishing documentation](https://docs.npmjs.com/trusted-publishers)
- [Announcement blog post](https://github.blog/changelog/2025-07-31-npm-trusted-publishing-with-oidc-is-generally-available/)
- [Provenance statements guide](https://docs.npmjs.com/generating-provenance-statements)

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the repository's package-publishing GitHub Actions workflow and the npm trusted publishing documentation linked in the issue. Configure the trusted publisher, grant id-token: write, remove NODE_AUTH_TOKEN, and verify that publishing and provenance generation work successfully.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, javascript, node.js
Domain
ci-cd, release, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.