banner
jviide.iki.fi
@jviide.iki.fi
Reposted
There are things I will not let go of, but I also don't want to become one of those permanently aggrieved people whose personality has been wholly replaced by three grudges in a trenchcoat.
December 1, 2025 at 12:43 AM
Yes.
October 9, 2025 at 1:08 PM
...or set up Trusted Publishing and delete all your NPM tokens 🙂

bsky.app/profile/sxzz...
We encourage everyone to migrate from using npm publish tokens to trusted publisher!

github.com/e18e/ecosyst...
September 17, 2025 at 9:45 PM
Pay special attention to "Automation" and "Publish" token types, as they aren't scoped and allow writes. They also never expire.

"Granular" ones are trickier. They MAY be read-only or tightly scoped. It's hard to tell, as the token page doesn't show this info. Their lifetimes can also be very long.
September 17, 2025 at 8:01 PM
FWIW, reported this to them via HackerOne yesterday. Got a prompt response back that this is a known low risk issue and that they don't consider this to present a significant security risk.
September 10, 2025 at 1:24 PM
t
August 21, 2025 at 3:00 PM