npm notice npm tokens that bypass 2FA are being restrictednpm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
Your release workflow publishes with a granular access token that has “bypass 2FA” enabled. npm is phasing that out:
For CI, the replacement is trusted publishing (OIDC). No token is stored at all.
npx go-tokenless # see the exact changes for your repo
npx go-tokenless apply # make them
Then add the trusted publisher. go-tokenless prints the npm trust github … command for each package, or you can add it on npmjs.com → package → Settings → Trusted publishing. Delete the old secret after the first tokenless release.
See the full checklist.