Skip to content

[npm] Support multiple trusted publishing workflows per package [GA] #1267

@glider-bot

Description

@glider-bot

Value Prop

You can now set up multiple trusted publishing workflows for each npm package, making it easy to publish stable releases, betas, and other versions from different CI workflows—all without relying on long-lived tokens. This gives you more flexibility and security, letting you use short-lived credentials for every publishing path.

Expected Outcome

By supporting multiple OIDC configurations per package and namespace, teams can fully retire long-lived publish tokens and streamline their release processes. This change aims to improve both the security and convenience of npm publishing for projects with complex or multi-path release workflows.

Metadata

Metadata

Assignees

No one assigned

    Labels

    FreeProduct SKU: GitHub Free

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Q3 2026 – Jul-Sep

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions