Skip to content

ci: add npm publish workflow with provenance (OIDC trusted publishing)#696

Open
NX1X wants to merge 1 commit into
JuliusBrussee:mainfrom
NX1X:npm-publish-provenance
Open

ci: add npm publish workflow with provenance (OIDC trusted publishing)#696
NX1X wants to merge 1 commit into
JuliusBrussee:mainfrom
NX1X:npm-publish-provenance

Conversation

@NX1X

@NX1X NX1X commented Jul 11, 2026

Copy link
Copy Markdown

Adds publish.yml to publish on release using npm Trusted Publishing (OIDC) +
--provenance — no long-lived NPM_TOKEN. Targets caveman-shrink;
caveman-installer is left commented out until/unless it's published to npm.

Requires a one-time Trusted Publisher setup on npmjs.com (this repo + publish.yml
as the trusted publisher for the package), documented in the workflow header. The
workflow is inert until a release is published and that setup is in place.

@NX1X
NX1X marked this pull request as draft July 11, 2026 12:04
@NX1X
NX1X marked this pull request as ready for review July 11, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant