Skip to content

Conversation

@belen-pruvost
Copy link
Contributor

@belen-pruvost belen-pruvost commented Nov 6, 2025

Note

Switches npm publish to OIDC with provenance and ignores scripts, removing the token-based publish step.

  • CI (.github/workflows/npm-publish.yaml):
    • Replace token-based npm publish with OIDC: npm publish --access public --provenance --ignore-scripts.
    • Remove NODE_AUTH_TOKEN usage in publish step.

Written by Cursor Bugbot for commit 041bf8e. Configure here.

Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment @cursor review or bugbot run to trigger another review on this PR

@belen-pruvost belen-pruvost requested a review from Pluies November 6, 2025 13:26
Copy link

@Pluies Pluies left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Woah! Nice!

@belen-pruvost belen-pruvost merged commit cd8bc34 into main Nov 6, 2025
2 checks passed
@belen-pruvost belen-pruvost deleted the use-trusted-publisher branch November 6, 2025 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants