npm の信頼設定に有効期限が付きました
💬 In one line
倉庫の管理者が npm に自動で公開する許可をするとき、その許可が 48 時間だけ有効になりました。
1 回目に無事に公開できたら、その許可は永遠に使えるようになります。
✨ Highlights
-
新しい許可は 48 時間だけ有効
倉庫の持ち主が変わった時に、古い許可が悪用されるのを防げます。
-
1 回目に成功したら永遠に使える
何度も許可をやり直さなくて済むので、手間が減ります。
-
公開の方法を変えないといけない場合がある
危ないやり方で npm に公開していたら、安全な方法に切り替える必要があります。
🛠️ What it means for your work
npm に自動で公開する許可を新しく作ったなら、48 時間以内に 1 回は公開テストをしてください。そうしないと許可が消えて、もう一度作り直さないといけません。もし公開の時に「issue_comment」という信号を使っていたら、「push」や「release」に変えてください。
⚠️ Watch out for
既に 1 回以上、無事に公開できている許可は影響を受けません。心配なら、自分の npm 設定ページを見て、有効期限がある許可がないか確認してください。
🔗 Original
This page is an AI summary of the official release notes. The full original text is not reproduced here.
Read the GitHub https://github.blog/changelog/2026-10-02-unvalidated-npm-trusted-publishing-configurations-now-expire release notes →🔗 Related hubs and releases in the same category
🔔 Get the next one
Get plain-Japanese write-ups of new GitHub releases without opening the site (twice a day). No email address required.
What is RSS: New items arrive automatically wherever you already read (a reader such as Feedly, Slack, n8n). Copy the URL above and paste it in — no sign-up, no cost.
The headline and summary are an AI's Japanese rendering of each company's official announcement. They can diverge from the original. For the exact wording, follow the link to the official page. Terms of Use