go-tokenless

npm notice npm tokens that bypass 2FA are being restricted

npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation

Your release workflow publishes with a granular access token that has “bypass 2FA” enabled. npm is phasing that out:

For CI, the replacement is trusted publishing (OIDC). No token is stored at all.

Migrate

npx go-tokenless          # see the exact changes for your repo
npx go-tokenless apply    # make them

Then add the trusted publisher. go-tokenless prints the npm trust github … command for each package, or you can add it on npmjs.com → package → Settings → Trusted publishing. Delete the old secret after the first tokenless release.

See the full checklist.

← All errors