-
Notifications
You must be signed in to change notification settings - Fork 0
feat(release): add trusted publish workflow with provenance #28
Copy link
Copy link
Closed
Labels
priority:mediumMedium priority for production readinessMedium priority for production readinessproduction-readinessProduction readiness hardening before public releaseProduction readiness hardening before public releasetype:ciContinuous integration and automationContinuous integration and automationtype:securitySecurity policy or supply-chain hardeningSecurity policy or supply-chain hardening
Metadata
Metadata
Assignees
Labels
priority:mediumMedium priority for production readinessMedium priority for production readinessproduction-readinessProduction readiness hardening before public releaseProduction readiness hardening before public releasetype:ciContinuous integration and automationContinuous integration and automationtype:securitySecurity policy or supply-chain hardeningSecurity policy or supply-chain hardening
Type
Fields
Give feedbackNo fields configured for issues without a type.
Problem
There is no tag-triggered release workflow, OIDC trusted publishing, npm provenance, crate dry-run gate, or artifact attestation.
Acceptance criteria