npm is implementing major security changes including shorter token lifetimes (7-day default, 90-day maximum), sunsetting classic tokens entirely, and disabling new TOTP 2FA setups in favor of WebAuthn. These changes roll out over five weeks through mid-November 2025. Package maintainers must migrate from classic tokens to

4m read timeFrom github.blog
Post cover image
Table of contents
What’s changingTimeline and implementationLooking ahead: Trusted publishersWe need your partnershipGetting supportThank you

Sort: