npm Trusted Publish Lint - OIDC & tokens

npm classic tokens were revoked 2025-12-09 and granular write tokens now expire in 90 days. Finds the token, OIDC and provenance gaps that will 401 your next release, in GitHub Actions and GitLab CI. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Finds the credential in your release workflow that expires before your next release

A freelance DevOps engineer is a median $60/hour on Upwork (typical range $40-$100); reading one release workflow and rewriting it for OIDC is most of an hour

Buy the full version — $29

Questions people ask

What does npm Trusted Publish Lint actually do?

It reads a release workflow, an .npmrc line or a package.json and reports every place your npm publish still leans on a credential with an expiry date. Fifteen rules cover stored tokens, missing id-token: write, missing provenance, mutable action refs and install scripts running beside your publish credential. Each finding lands on its own line with the fix named.

Who is this for?

Node package maintainers and release engineers who publish to npm from GitHub Actions or GitLab CI - the solo maintainer with one publish.yml, and the platform engineer who owns forty of them in a monorepo. If your release job still carries NODE_AUTH_TOKEN or an .npmrc line, every rule here is about your file.

Why is npm audit or a secret scanner not enough?

npm audit reads your dependency tree, not your workflow, and a secret scanner only fires on a literal token you committed. Neither one knows that classic tokens were revoked on 2025-12-09, that a granular write token cannot outlive 90 days, or that trusted publishing needs id-token: write in that exact job.

What is free and what costs money?

Free is the whole check: all 15 rules, every line, every file you open, in the editor or in the browser, with no key and no account. The paid layer changes what you take away - it sweeps every workflow in the repository in one pass and writes the audit to a dated Markdown or CSV file.

What would this cost me otherwise?

A freelance DevOps engineer is a median $60 an hour on Upwork, with the usual range running $40 to $100. Reading one release workflow line by line, checking it against npm's current token rules and rewriting it for OIDC is most of an hour. The extension is $29 once.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool