Supply-chain securitynpm trusted publishing finally covers dist-tags, if you ask nicely
GitHub has extended npm trusted publishing to cover dist-tag changes under short-lived OIDC credentials, but the new permission ships off by default on every configuration.