What's the point of npm trusted publishing? Any first time publish requires a token, local `npm publish` saves a publishing token that never expire, which can do perma-damage if stolen. Chance of me getting fucked is increasing while I make this post. Who the fuck remembers to delete this shit?
32 likes 6 replies
?