GitHub’s changelog for 30 September 2026 says an npm trusted-publishing configuration can be granted permission to manage dist-tags. That covers promoting a version to latest and moving next or beta, using the short-lived OIDC credential from the workflow instead of a long-lived access token. The post says trusted publishing already covered publishing and staging, and that tag changes were the gap that kept a granular token around after a release or a rollback.
Defaults and scope
Each trusted-publishing configuration has an opt-in setting named Allow npm dist-tag. It defaults to off for new configurations and for ones that already exist, so turning the feature on in the product does not give every workflow new rights. The permission is separate from the right to publish a package. A configuration that can only stage a release can still be allowed to move tags. GitHub says a tag operation is authorized when the incoming OIDC token matches any one configuration that has the permission enabled. Token-based tag management is unchanged.
The setup step on the page is: open the package’s trusted publishing settings and enable Allow npm dist-tag on the configurations that should manage tags. The post does not show a CLI flag or a JSON field name. It points to GitHub’s existing documentation on trusted publishers for npm.
Practical takeaway
If your release workflow still stores an npm token only to run npm dist-tag after publish, this is the opt-in that removes that token, on the configurations you mark. Leave it off where a workflow should publish or stage without being able to move latest. Because any one matching configuration is enough, review every trusted-publisher entry on the package, not only the one you use for production.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.