npm's stage-only token scope puts a human between CI and the registry
GitHub added a Read and write (stage only) scope to npm granular access tokens. A workflow with the new scope can stage a package version for review, but it cannot publish; a maintainer has to approve the release through 2FA before it goes live.