We need to work with the squads to migrate all of NPM publication workflows from using tokens to trusted publishers. See [Github response to Shai-Hulud](https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/) and [NPM trusted publisher doc](https://docs.npmjs.com/trusted-publishers).