Skip to content

Drop --provenance flag for private repo, bump to 0.2.5#18

Merged
sdserranog merged 1 commit intomainfrom
sdserranog/fix-npm-trusted-pub
Mar 5, 2026
Merged

Drop --provenance flag for private repo, bump to 0.2.5#18
sdserranog merged 1 commit intomainfrom
sdserranog/fix-npm-trusted-pub

Conversation

@sdserranog
Copy link
Copy Markdown
Contributor

Summary

  • Removes --provenance from npm publish — provenance attestation requires a public source repo, but OIDC auth (Trusted Publishers) works without it
  • Bumps to 0.2.5 to trigger release on merge

Note

Add --provenance back when the repo is made public for supply chain attestation.

Test plan

  • Release workflow succeeds on merge
  • npm view @arcadeai/create-agent version returns 0.2.5

🤖 Generated with Claude Code

Provenance attestation requires a public source repository.
OIDC trusted publishing auth works independently of --provenance.
Add --provenance back when the repo is made public.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@sdserranog sdserranog merged commit 3c0a2c5 into main Mar 5, 2026
@sdserranog sdserranog deleted the sdserranog/fix-npm-trusted-pub branch March 5, 2026 00:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant