go-tokenless

Publishing still uses NPM_TOKEN after the migration

You added id-token: write and a trusted publisher, but releases still use the old token. Revoking it breaks publishing, and the provenance badge is missing.

npm tries OIDC first but falls back to a configured token. Any token that reaches the publish step keeps the old credential in use. Look for these:

If installs need private packages, keep a read-only token on the install step only (npm ci), not on the publish.

Find them automatically

npx go-tokenless                          # lists every token that still reaches publishing
npx go-tokenless apply --read-token NPM_READ_TOKEN   # removes them; installs get a read-only token

← All errors