Joachim Viide
banner
jviide.iki.fi
Joachim Viide
@jviide.iki.fi
https://jviide.iki.fi • A cruel and incompetent charlatan.
Yes.
October 9, 2025 at 1:08 PM
...or set up Trusted Publishing and delete all your NPM tokens 🙂

bsky.app/profile/sxzz...
We encourage everyone to migrate from using npm publish tokens to trusted publisher!

github.com/e18e/ecosyst...
September 17, 2025 at 9:45 PM
Pay special attention to "Automation" and "Publish" token types, as they aren't scoped and allow writes. They also never expire.

"Granular" ones are trickier. They MAY be read-only or tightly scoped. It's hard to tell, as the token page doesn't show this info. Their lifetimes can also be very long.
September 17, 2025 at 8:01 PM
FWIW, reported this to them via HackerOne yesterday. Got a prompt response back that this is a known low risk issue and that they don't consider this to present a significant security risk.
September 10, 2025 at 1:24 PM
t
August 21, 2025 at 3:00 PM
Reposted by Joachim Viide
July 30, 2024 at 2:41 AM