Skip to content

Commit d6f084b

Browse files
committed
chore: generate provenance statements on release
1 parent f7bc402 commit d6f084b

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

.github/workflows/release.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,8 @@ jobs:
2121
outputs:
2222
published_packages: ${{ steps.changesets.outputs.publishedPackages }}
2323
published: ${{ steps.changesets.outputs.published }}
24+
permissions:
25+
id-token: write # to enable use of OIDC for npm provenance
2426
steps:
2527
- name: ⬇️ Checkout repo
2628
uses: actions/checkout@v4
@@ -62,6 +64,7 @@ jobs:
6264
createGithubReleases: false
6365
env:
6466
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
67+
NPM_CONFIG_PROVENANCE: true
6568
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
6669

6770
find_package_version:

0 commit comments

Comments
 (0)