Commit 2d65351
authored
ci(release): switch npm publish to provenance-based auth (#209)
Add explicit permissions for OIDC token and contents access.
Remove NODE_AUTH_TOKEN in favor of npm provenance publishing,
which provides stronger supply chain security guarantees.
Signed-off-by: Kevin Cui <bh@bugs.cc>1 parent 6a91a94 commit 2d65351
1 file changed
+4
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
7 | 11 | | |
8 | 12 | | |
9 | 13 | | |
| |||
47 | 51 | | |
48 | 52 | | |
49 | 53 | | |
50 | | - | |
51 | | - | |
| |||
0 commit comments