npm trusted publishing can now move dist-tags without a long-lived token
GitHub has extended npm trusted publishing to cover dist-tags. Trusted publishing configurations can now be given permission to manage tags, such as promoting a version to latest or moving the next and beta pointers, using short-lived OIDC credentials instead of a long-lived access token.
Until now trusted publishing covered publishing and staging but not tag operations. GitHub says that left maintainers who had otherwise moved to token-free, OIDC-based workflows still holding a granular access token for one job: managing tags after a release or a rollback.
Each trusted publishing configuration now has an opt-in setting, Allow npm dist-tag. It is off by default for both new and existing configurations, so no configuration gains a capability automatically. The permission is independent of direct publishing, which means a configuration that only stages packages can still be allowed to manage tags. A dist-tag operation is authorised if the incoming OIDC token matches any one configuration that has the permission enabled.
Existing token-based tag management keeps working unchanged. The setting is enabled per configuration in a package's trusted publishing settings.

Why it matters
A token kept only for dist-tags is still a long-lived secret that can move latest to any published version, and latest is what most installs resolve to. Closing that last use lets maintainers delete the token entirely. Because the permission matches any configuration that has it, the safe pattern is to enable it only on the workflow that actually performs releases.