Sfoglia il codice sorgente

ci: use trusted publishing (OIDC provenance)

Tobi Lutke 3 mesi fa
parent
commit
ee58a685de
1 ha cambiato i file con 2 aggiunte e 3 eliminazioni
  1. 2 3
      .github/workflows/publish.yml

+ 2 - 3
.github/workflows/publish.yml

@@ -10,6 +10,7 @@ jobs:
 
     permissions:
       contents: write
+      id-token: write
 
     steps:
       - uses: actions/checkout@v4
@@ -29,9 +30,7 @@ jobs:
           node-version: 22
           registry-url: https://registry.npmjs.org
 
-      - run: npm publish --access public
-        env:
-          NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
+      - run: npm publish --provenance --access public
 
       - name: Create GitHub Release
         env: