we now have some new @e18e.dev docs on best practice of publishing npm packages this documents the recommended basics for a secure publish workflow and gives some pointers for further security/tools/etc this is a _very_ opinionated subject, so do ping me if you have feedback!
e18e (Ecosystem Performance) - Publishing Packages
Best practices on publishing npm packages securely using GitHub Actions.
e18e.dev