Skip to content

Conversation

pull[bot]
Copy link

@pull pull bot commented Jul 30, 2025

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.3)

Can you help keep this open source service alive? 💖 Please sponsor : )

reggi and others added 2 commits July 30, 2025 15:26
When someone with a public repository and a private package attempts to
publish with OIDC, the publish command will fail because provenance is
enabled, there is currently no visibility check before auto enabling
provenance.

This is a very rare edge case, but it's still incorrect. OIDC will
always gracefully fail, but provenance does not.

* This fix adds all the provenance related code after the OIDC auth
token is set.
* This requires provenance to be in the default config state (not set by
the user) for OIDC to even consider auto-enabling provannece.

---------

Co-authored-by: Gar <[email protected]>
@pull pull bot locked and limited conversation to collaborators Jul 30, 2025
@pull pull bot added the ⤵️ pull label Jul 30, 2025
@pull pull bot merged commit d006583 into NOUIY:latest Jul 30, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant