We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent d400bd3 commit 99ab48bCopy full SHA for 99ab48b
.github/workflows/semantic-release.yml
@@ -5,14 +5,17 @@ on:
5
branches:
6
- main
7
8
+# OIDC Trusted Publishing - npm provenance for signed packages
9
+# See: https://docs.npmjs.com/generating-provenance-statements
10
+
11
jobs:
12
release:
13
runs-on: ubuntu-latest
14
permissions:
15
contents: write
16
issues: write
17
pull-requests: write
- id-token: write
18
+ id-token: write # Required for OIDC trusted publishing
19
20
steps:
21
- name: Checkout
@@ -41,4 +44,5 @@ jobs:
41
44
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
42
45
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
43
46
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
47
+ NPM_CONFIG_PROVENANCE: true
48
run: npx semantic-release
0 commit comments