Dated evidence card
Current version, registry attestation-metadata state, declared repository route, and visible workflow-path signals from public sources.
01 Release-Path Rescue
GitHub and npm say bypass-2FA tokens are expected to lose direct publishing around January 2027. ReleaseOrigin maps one visible release path to direct OIDC, staged publishing, verification-only, or no-fit—and hands every state-changing step back to your publisher.
Registry + public release-path evidence
Enter an exact package name. ReleaseOrigin reads public npm metadata and, only when requested, the package-declared public repository. It never installs or runs the package.
Point-in-time public evidence only. A classifier result needs owner review; missing attestation metadata is not a security, compliance, or migration verdict.
02 The handoff
Every accepted pilot is bounded to one path. The public sample and templates deliberately stop before publication.
Current version, registry attestation-metadata state, declared repository route, and visible workflow-path signals from public sources.
A concise decision—direct OIDC, staged publishing, verification-only, or no-fit—based on the visible path and current provider constraints.
An OIDC or staged-publishing patch when the supported hosted CI path, package configuration, and public release evidence are compatible.
The npm account and trusted-publisher settings your authorized publisher completes. Credentials never belong in the handoff.
Static, non-executing review plus an owner-run dry-run checklist for the customer’s controlled environment after review.
An owner-run retry and post-release verification sequence, rollback notes, and one consolidated revision after review.
One npm package · one public repository · one visible release workflow · one supported hosted CI path · one consolidated revision. We decline before charging when the public path cannot support a concrete handoff. The pilot does not include monorepo-wide migration, private repository review, registry administration, package publication, or ongoing release operations.
03 Inspect before inquiry
Review a fictional, non-client handoff: sanitized evidence, a path decision, static validation, an owner-run retry checklist, and rollback notes.
registry.latestREADrepo.workflowMAPworkflow.static_checkVERIFYowner.publishSTOP / HANDOFF04 Fit gate
Provider support and npm requirements can change. The accepted scope records the provider, package, workflow, and direct-versus-staged assumptions used for the handoff. See the current decision guide.
05 24-hour rescue route
The delivery clock starts only after written fit and scope confirmation, public inputs, and agreed payment are received.
Lock the package, repository, workflow, hosted CI path, and release owner.
Map the visible release to direct OIDC, staged publishing, verification-only, or no-fit using npm’s current guidance.
Prepare the bounded patch, complete static checks, and give the owner a controlled-environment rehearsal and retry checklist.
Your authorized maintainer reviews, configures the trusted publisher, merges, and runs the release.
06 Claim boundary
GitHub and npm currently target around January 2027 for bypass-2FA tokens to lose direct publishing. npm documents Trusted Publishing as an OIDC-based alternative, and staged publishing as a route with human 2FA approval.
Attestations can connect published artifacts to source and build information. Their presence does not prove that code is safe or non-malicious; their absence does not establish insecurity, negligence, a policy violation, or noncompliance.
ReleaseOrigin is not a security audit, compliance assessment, penetration test, code review, or certification.
07 Start with fit
This creates a fit-review inquiry, not a checkout or automatic booking. We reply after reviewing the public package and package-declared repository path.
Do not send tokens, passwords, API keys, private links, customer data, file contents, attachments, or credentials. The form rejects unsupported fields and credential-like content.