2
2 Comments

Check out my latest write-up on CoderLegion: "Who Can Change Your npm Release Tags?"

https://coderlegion.com/29397/who-can-change-your-npm-release-tags

Read the full article here: https://coderlegion.com/29397/who-can-change-your-npm-release-tags

#DevCommunity #Tech

submitted this linkon October 1, 2026
  1. 1

    Release-tag permissions are one of those "boring until it is catastrophic" topics. A lot of teams treat npm access like a personal account forever, then discover a contractor still has publish rights months later.

    Worth spelling out who can move latest vs who can only push prereleases. That split alone prevents a class of accidental production bumps.

    Did the write-up cover org-level 2FA / granular tokens, or mostly the tag semantics? Both matter in practice.

    1. 1

      That’s a great point! The post mainly focuses on tag-management permissions and OIDC-based trusted publishing, but org-level 2FA and granular token controls are equally important. Separating who can publish prereleases from who can move latest adds another useful layer of protection against accidental production releases.