Zach Leatherman 12/4/2025

No more tokens! Locking down npm Publish Workflows

Read Original

This article details a security review of npm publishing workflows, prompted by high-profile supply chain attacks. It analyzes recent incidents like Shai Halud and DuckDB compromises, then provides a practical checklist for locking down CI/CD pipelines. Recommendations include using granular tokens, enforcing 2FA, and moving away from token-based authentication in GitHub Actions to mitigate risks.

No more tokens! Locking down npm Publish Workflows

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week