npm is deprecating tokens that bypass 2FA for direct publish, and the
NPM_TOKEN secret's automation token didn't have that bypass enabled
anyway (publish failed with EOTP). Trusted publishing authenticates
CI via GitHub's OIDC token instead, so no npm secret is stored in the
repo at all. Requires the npm CLI to be >= 11.5.1, hence the npm
self-update step, and requires a Trusted Publisher to be configured
on the maskshift package (npmjs.com -> Package Settings -> Trusted
Publisher -> GitHub Actions, repo nafeeur/MaskShift, workflow
publish.yml, direct publish allowed).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016V9VYdmxCC2RKY6Ba8JYTg