Skip to content

Conversation

@cristianoventura
Copy link
Contributor

We want to harden how packages are published to NPM. We’ll do this by exclusively using NPM Trusted Publishing instead of NPM tokens.

Some pre-work has been done before this PR:

  • A new environment named RELEASE has been created in GitHub
  • Trusted publishing has been enabled in NPM

This PR replaces the NPM token and specifies the RELEASE environment during publishing so the release can be trusted by NPM.

@cristianoventura cristianoventura self-assigned this Oct 10, 2025
@cristianoventura cristianoventura requested a review from a team as a code owner October 10, 2025 16:09
@github-actions

This comment has been minimized.

Copy link
Contributor

@2Steaks 2Steaks left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a zizmor issue to fix, otherwise, code looks good!

Copy link
Contributor

@2Steaks 2Steaks left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cristianoventura cristianoventura merged commit f5d0428 into master Oct 15, 2025
6 checks passed
@cristianoventura cristianoventura deleted the internal/enable-npm-trusted-publishing branch October 15, 2025 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants