l8r Twats Library

@mitsuhiko

Post

Is there really still no reasonable process to set up this damn trusted publishing on npm for new packages without having agent go to the settings pages in Chrome with my help?

Explanation

What it says Armin Ronacher is frustrated that setting up npm trusted publishing for a brand-new package still seems to require manually navigating npm’s web settings in Chrome, even when an agent is doing the rest of the release workflow.

Context “Trusted publishing” refers to publishing packages via an identity-based CI/OIDC flow rather than storing a long-lived npm access token. The post’s specific complaint is about bootstrapping/configuration: apparently the initial trust relationship for a new package cannot be established through a clean agent/API/CLI workflow. The post does not provide the exact npm UI steps or identify which automation path Ronacher tried.

Why it matters This is a sharp example of an agentic-development bottleneck: the coding, testing, and release process can be automated, yet one browser-only administrative step keeps a human in the loop. For people building autonomous coding/release agents, APIs for initial repository/package permissions and trust configuration matter almost as much as APIs for publishing itself.