Skip to content
Brief Security & Trust ·

npm trusted publishing setups now lapse after 48 hours if never used

GitHub says npm trusted publishing setups that were never validated now expire, and one workflow trigger is now refused.

In brief
  • GitHub said on 2 October 2026 that npm trusted publishing setups lapse after 48 hours unless one publish has succeeded.
  • npm also now refuses trusted publishing tokens from GitHub Actions runs triggered by issue_comment.

GitHub said on 2 October 2026 that npm trusted publishing setups now lapse after 48 hours if they were never validated. A lapsed setup cannot approve a release. One successful publish validates a setup and ends the countdown. GitHub also said npm now refuses tokens from GitHub Actions runs triggered by issue_comment, joining an existing limit on pull_request_target.

GitHub said the deadline reduces the danger of trusting a repository or project once someone else takes it over. Changing the repository or project identity starts a new 48-hour window, but ordinary edits do not. Expired setups stay visible in settings, and other valid setups on the package are unaffected. Recreating a setup restarts the clock. The post gives no count of affected setups.

Explanation, not GitHub's claim: trusted publishing lets a build job prove its identity to npm and get a short-lived token, so no long-term password is stored. That trust points at a name, and a name can change owners. Comment-triggered runs can be started by outsiders, so they are a risky place for publishing power. Leaders should ask who owns each setup, whether any were made and never used, and whether any release runs from a comment event. GitHub suggests push, release or workflow_dispatch instead.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: GitHub.