jakub_g 10 hours ago

[September 29, 2025]

> Over the next five weeks, we will:

> Revoke all existing legacy classic tokens for npm publishers.

> Disable legacy classic token generation on npmjs.com permanently.

> If you use classic tokens for npm, you must immediately take the following actions:

> Generate new npm granular access tokens with appropriate scoped permissions.

> Update all automation, CI/CD pipelines, and local configurations.