{
  "id": 13015992,
  "title": "Build & Release #3: I Deleted Every npm Token I Own",
  "url": "https://urgent.news/2026/10/09/build-release-3-i-deleted-every-npm-token-i-own",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T03:15:27.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/7onic/build-release-2-i-deleted-every-npm-token-i-own-1o87"
  },
  "original_language": "en",
  "account": "On October 7th, the reporter attempted to publish a package on npm but encountered four consecutive failures, each resulting in a 404 error. The package, @7onic-ui/tokens@0.3.7, had been published multiple times before from the same workflow with no issues. The first failure was due to the NPM_TOKEN secret being expired, while the subsequent failures were caused by the token being empty or incorrect in the GitHub secrets panel. After deleting all npm tokens and the NPM_TOKEN secret from GitHub, publishing worked seamlessly. The reporter then switched to using Trusted Publishing, a more secure method that replaces the shared-secret model with a question npm asks GitHub directly. This migration involved registering the publisher once per package and deleting the NPM_TOKEN secret from GitHub. Once completed, the reporter successfully published packages without any authentication issues.",
  "summary": "On October 7th I tried to publish @7onic-ui/tokens@0.3.7 and npm told me my own package didn't exist. npm error 404 Not Found - PUT https://registry.npmjs.org/@7onic-ui%2ftokens npm error 404 '@7onic-ui/tokens@0.3.7' is not in this registry. A 404. On a PUT. For a package I'd published more than a dozen times before, from the same workflow. The release itself was as ready as a release gets —…",
  "key_points": [
    "Reporter deleted all npm tokens and NPMTOKEN secret from GitHub",
    "Switched to Trusted Publishing for secure package publishing",
    "Successfully published packages without authentication issues"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}