<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Npm on Kuldeep Pisda</title><link>https://kdpisda.in/tag/npm/</link><description>Recent content in Npm on Kuldeep Pisda</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 11 Oct 2026 08:30:00 +0530</lastBuildDate><atom:link href="https://kdpisda.in/tag/npm/index.xml" rel="self" type="application/rss+xml"/><item><title>npm Trusted Publishing Configs Now Expire in 48 Hours Unless a Publish Validates Them</title><link>https://kdpisda.in/npm-trusted-publishing-48-hour-expiry-unvalidated-config/</link><pubDate>Sun, 11 Oct 2026 08:30:00 +0530</pubDate><guid>https://kdpisda.in/npm-trusted-publishing-48-hour-expiry-unvalidated-config/</guid><description>&lt;p&gt;If you set up an npm trusted publisher and do not complete a publish from it within two days, it stops working. That is the behavior GitHub announced on &lt;a href="https://github.blog/changelog/2026-10-02-unvalidated-npm-trusted-publishing-configurations-now-expire"&gt;October 2&lt;/a&gt;: configurations that have never been validated by a successful publish expire 48 hours after creation and can no longer authorize publishing. The same change adds a second restriction, covered below, for workflows triggered by &lt;code&gt;issue_comment&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;This reads like housekeeping. It is closer to a fix for a specific hole in how trust is declared.&lt;/p&gt;</description></item></channel></rss>