[{"data":1,"prerenderedAt":88},["ShallowReactive",2],{"blog-stage-only-npm-tokens-for-safer-automation":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"tags":11,"cover":17,"body":18,"_type":82,"_id":83,"_source":84,"_file":85,"_stem":86,"_extension":87},"/blog/stage-only-npm-tokens-for-safer-automation","blog",false,"","Stage-only npm tokens for safer automation","GitHub introduces 'Read and write (stage only)' tokens for npm to enhance security in automated workflows.","2026-09-19",[12,13,14,15,16],"npm","automation","security","github","devops",true,{"type":19,"children":20,"toc":76},"root",[21,30,44,50,55,60,66,71],{"type":22,"tag":23,"props":24,"children":26},"element","h2",{"id":25},"granular-access-for-safer-automation",[27],{"type":28,"value":29},"text","Granular Access for Safer Automation",{"type":22,"tag":31,"props":32,"children":33},"p",{},[34,36,42],{"type":28,"value":35},"GitHub now offers a new granular access token scope: ",{"type":22,"tag":37,"props":38,"children":39},"strong",{},[40],{"type":28,"value":41},"Read and write (stage only)",{"type":28,"value":43}," when creating npm tokens. This scope allows automated workflows to stage package versions for review without granting full publishing rights.",{"type":22,"tag":23,"props":45,"children":47},{"id":46},"why-stage-only-tokens-matter",[48],{"type":28,"value":49},"Why Stage-Only Tokens Matter",{"type":22,"tag":31,"props":51,"children":52},{},[53],{"type":28,"value":54},"Staging package versions before final release is a common practice to ensure quality and compliance. However, giving automated workflows broad publishing access can introduce security risks if tokens are compromised.",{"type":22,"tag":31,"props":56,"children":57},{},[58],{"type":28,"value":59},"The stage-only access reduces these risks by limiting token permissions strictly to staging activities, adding an important layer of security in continuous integration and delivery pipelines.",{"type":22,"tag":23,"props":61,"children":63},{"id":62},"impact-on-development-pipelines",[64],{"type":28,"value":65},"Impact on Development Pipelines",{"type":22,"tag":31,"props":67,"children":68},{},[69],{"type":28,"value":70},"Automated systems can now rely on scoped tokens that enforce the principle of least privilege. This enhances approval workflows and reduces the attack surface for supply chain security threats.",{"type":22,"tag":31,"props":72,"children":73},{},[74],{"type":28,"value":75},"Secure and efficient management of package publishing is critical as development cycles accelerate. This update aligns perfectly with the need for both speed and safety.",{"title":7,"searchDepth":77,"depth":77,"links":78},2,[79,80,81],{"id":25,"depth":77,"text":29},{"id":46,"depth":77,"text":49},{"id":62,"depth":77,"text":65},"markdown","content:blog:stage-only-npm-tokens-for-safer-automation.md","content","blog/stage-only-npm-tokens-for-safer-automation.md","blog/stage-only-npm-tokens-for-safer-automation","md",1789802318579]