GitHub said on 2 October 2026 that npm trusted publishing setups now lapse after 48 hours if they were never validated. A lapsed setup cannot approve a release. One successful publish validates a setup and ends the countdown. GitHub also said npm now refuses tokens from GitHub Actions runs triggered by issue_comment, joining an existing limit on pull_request_target.
GitHub said the deadline reduces the danger of trusting a repository or project once someone else takes it over. Changing the repository or project identity starts a new 48-hour window, but ordinary edits do not. Expired setups stay visible in settings, and other valid setups on the package are unaffected. Recreating a setup restarts the clock. The post gives no count of affected setups.
Explanation, not GitHub's claim: trusted publishing lets a build job prove its identity to npm and get a short-lived token, so no long-term password is stored. That trust points at a name, and a name can change owners. Comment-triggered runs can be started by outsiders, so they are a risky place for publishing power. Leaders should ask who owns each setup, whether any were made and never used, and whether any release runs from a comment event. GitHub suggests push, release or workflow_dispatch instead.