Build & Release #3: I Deleted Every npm Token I Own
On October 7th I tried to publish @7onic-ui/tokens@0.3.7 and npm told me my own package didn't exist. npm error 404 Not Found - PUT https://registry.npmjs.org/@7onic-ui%2ftokens npm error 404 '@7onic-ui/tokens@0.3.7' is not in this registry. A 404. On a PUT. For a package I'd published more than a dozen times before, from the same workflow. The release itself was as ready as a release gets —…
On October 7th, the reporter attempted to publish a package on npm but encountered four consecutive failures, each resulting in a 404 error. The package, @7onic-ui/tokens@0.3.7, had been published multiple times before from the same workflow with no issues. The first failure was due to the NPM_TOKEN secret being expired, while the subsequent failures were caused by the token being empty or incorrect in the GitHub secrets panel.
After deleting all npm tokens and the NPM_TOKEN secret from GitHub, publishing worked seamlessly. The reporter then switched to using Trusted Publishing, a more secure method that replaces the shared-secret model with a question npm asks GitHub directly. This migration involved registering the publisher once per package and deleting the NPM_TOKEN secret from GitHub. Once completed, the reporter successfully published packages without any authentication issues.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.