Read the full article here: https://coderlegion.com/29397/who-can-change-your-npm-release-tags
#DevCommunity #Tech
Release-tag permissions are one of those "boring until it is catastrophic" topics. A lot of teams treat npm access like a personal account forever, then discover a contractor still has publish rights months later.
Worth spelling out who can move latest vs who can only push prereleases. That split alone prevents a class of accidental production bumps.
Did the write-up cover org-level 2FA / granular tokens, or mostly the tag semantics? Both matter in practice.
That’s a great point! The post mainly focuses on tag-management permissions and OIDC-based trusted publishing, but org-level 2FA and granular token controls are equally important. Separating who can publish prereleases from who can move latest adds another useful layer of protection against accidental production releases.