GitHub announced an additional permission for npm trusted publishing on September 30, 2026. A dist-tag is a label such as latest or beta that points users to a package version. Maintainers could already publish through short-lived OIDC credentials, but tag changes still required an access token in some release workflows. The new permission covers that remaining action. Source

An explicit setting

Allow npm dist-tag is off by default for both existing and newly created trusted publishing configurations. A maintainer must enable it in the package’s trusted publishing settings. It is separate from permission to publish a package, so a configuration used only for staging can receive tag-management rights if that matches the maintainer’s workflow. Source

What happens to existing automation

A tag operation is permitted when its OIDC token matches a configuration with this permission. Existing token-based tag management remains available. Teams can therefore assess whether to replace a stored token without treating the announcement as a forced migration or assuming that their current configurations automatically gained the new right. Source