Stage-only npm tokens for safer automation
UpdateVerifiedAdded Sep 22, 2026
You can now select Read and write (stage only) when creating an npm granular access token. This lets your automated workflows stage package versions for review without giving the token permission to publish new versions directly to the npm registry. Your workflow uses npm stage publish to submit a version.
Topics: Governance, Security, Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 18 | Manage the code coverage ruleset condition with the REST API GA | GA |
| Sep 16 | Code scanning AI Scan no longer requires CodeQL default setup Preview | Preview |
| Sep 21 | GitHub Enterprise adds credential inventory exports Update | Update |
| Sep 15 | Enforce GitHub Advanced Security configurations Update | Update |
| Sep 22 | Security improvements for SSH Update | Update |
| Sep 22 | Deprecation notice: All-platform CodeQL bundle Deprecation | Deprecation |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Sep 9 | npm extends recovery-code security holds to all accounts Update | Update |