NPM tokens without an expiry [are being dropped](https://github.blog/changelog/2025-09-29-strengthening-npm-security-important-changes-to-authentication-and-token-management/). We should switch to an NPM [trusted publisher](https://docs.npmjs.com/trusted-publishers) workflow for publishing packages, similar to PyPI. Affected repositories include: - [x] https://github.com/jupyterhub/configurable-http-proxy - [ ] https://github.com/jupyterhub/jupyter-server-proxy