Skip to content

Conversation

@MathieuGilbert
Copy link
Member

@MathieuGilbert MathieuGilbert commented Oct 16, 2025

NPM announcement strongly encouraging the use of OIDC, and the disabling of long-lived tokens mid-November.

Is this PR a bug fix, new feature, or security update?

  • Change to NPM publish auth.
  • Security update: 7 vulnerabilities (1 low, 2 moderate, 3 high, 1 critical)

Please describe this pull request:

PR Review Checklist

  • I have passing tests run via npm run test with a 100% coverage threshold
  • I have updated the version in package.json
  • I have updated any relevant documentation in README.md, .github, etc.
  • I have not included any secret values or links to internal AMA URLs in my commits or PR message

@MathieuGilbert MathieuGilbert requested a review from a team as a code owner October 16, 2025 19:02
Copy link

@amaValeriya amaValeriya left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't have access to npm to verify what you mentioned in the test steps, but I have no reason not to trust you.

@MathieuGilbert MathieuGilbert merged commit 6f89405 into master Oct 16, 2025
20 checks passed
@MathieuGilbert MathieuGilbert deleted the publish-using-oidc branch October 16, 2025 19:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants