Stage-only npm tokens for safer automation

GitHub introduced granular npm access tokens with a stage-only read and write permission. This allows automated workflows to stage package versions for manual review via npm stage publish without permitting direct publishing. Maintainers must approve these staged packages using two-factor authentication, helping mitigate the risk of automated credential compromise.