Skip to content

Commit 91d4962

Browse files
committed
fix: generate provenance statements on release
1 parent 4dc7caa commit 91d4962

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

.github/workflows/release.yml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,12 @@ concurrency:
1515
group: release
1616
cancel-in-progress: false
1717

18+
permissions:
19+
contents: write # to be able to publish a GitHub release
20+
id-token: write # to enable use of OIDC for npm provenance
21+
issues: write # to be able to comment on released issues
22+
pull-requests: write # to be able to comment on released pull requests
23+
1824
jobs:
1925
publish:
2026
name: Publish NPM package
@@ -37,7 +43,8 @@ jobs:
3743
run: npm run build
3844

3945
- name: Release new version
46+
run: npx semantic-release
4047
env:
4148
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
49+
NPM_CONFIG_PROVENANCE: true
4250
NPM_TOKEN: ${{ secrets.NPM_AUTOMATION_TOKEN }}
43-
run: npx semantic-release

0 commit comments

Comments
 (0)