Skip to content

Conversation

@ryoppippi
Copy link
Member

@ryoppippi ryoppippi commented Dec 15, 2025

Summary by cubic

Enable npm provenance in the release workflow by adding the --provenance flag to pnpm publish. This adds build attestation to releases for better supply chain verification, with no runtime or API changes.

Written for commit 0b1fe45. Summary will update automatically on new commits.

@ryoppippi ryoppippi requested a review from a team as a code owner December 15, 2025 14:05
Copilot AI review requested due to automatic review settings December 15, 2025 14:05
@pkg-pr-new
Copy link

pkg-pr-new bot commented Dec 15, 2025

Open in StackBlitz

npm i https://pkg.pr.new/StackOneHQ/stackone-ai-node/@stackone/ai@236

commit: 0b1fe45

@ryoppippi ryoppippi enabled auto-merge (squash) December 15, 2025 14:06
Copy link
Contributor

@glebedel glebedel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ryoppippi ryoppippi merged commit a784cd4 into main Dec 15, 2025
16 checks passed
@ryoppippi ryoppippi deleted the enable-provance branch December 15, 2025 14:10
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR enables provenance attestation for the npm package publishing process. Provenance provides transparency about where and how the package was built, enhancing supply chain security.

  • Adds the --provenance flag to the pnpm publish command to enable automatic generation of provenance attestation

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants