Skip to content

Conversation

@Alessandro100
Copy link
Contributor

@Alessandro100 Alessandro100 commented Oct 21, 2025

With the new NPM security updates coming out soon, we will need to change our authentication strategy when publishing packages

Instead of rotating tokens every 90 days, we will use npm's trusted publishers as a method of authentication. We will no longer need to handle NPM TOKENs

Proof of success
https://github.com/MobilityData/gbfs-json-schema/actions/runs/18689353734/job/53290636729

image

Copy link
Contributor

@fredericsimard fredericsimard left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@emmambd emmambd linked an issue Oct 21, 2025 that may be closed by this pull request
@Alessandro100 Alessandro100 merged commit 43c94b0 into master Oct 28, 2025
3 checks passed
@Alessandro100 Alessandro100 deleted the fix/update-npm-token-to-trusted-publisher branch October 28, 2025 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update NPM token process

3 participants