From eaa841df872e606cf20cc4ffe56201d27347afba Mon Sep 17 00:00:00 2001 From: Luca Forstner Date: Mon, 20 Apr 2026 21:01:51 +0200 Subject: [PATCH] chore: Fix publish by setting npm provenance and nulling auth --- .github/workflows/publish-js-sdk.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/publish-js-sdk.yaml b/.github/workflows/publish-js-sdk.yaml index beb957c9a..a53a154cb 100644 --- a/.github/workflows/publish-js-sdk.yaml +++ b/.github/workflows/publish-js-sdk.yaml @@ -22,6 +22,7 @@ concurrency: env: HUSKY: "0" + NPM_CONFIG_PROVENANCE: "true" jobs: stable-release: @@ -55,6 +56,8 @@ jobs: run: pnpm run build - name: Publish stable packages to npm if: steps.detect.outputs.needs_publish == 'true' + env: + NODE_AUTH_TOKEN: "" run: pnpm exec changeset publish - name: Push Changesets release tags if: steps.detect.outputs.has_work == 'true' @@ -135,6 +138,7 @@ jobs: permissions: contents: read id-token: write + environment: npm-publish steps: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: @@ -162,6 +166,8 @@ jobs: run: pnpm run build - name: Publish prerelease packages to npm if: steps.manifest.outputs.has_packages == 'true' + env: + NODE_AUTH_TOKEN: "" run: pnpm exec changeset publish --tag rc --no-git-tag - name: Post prerelease to Slack if: steps.manifest.outputs.has_packages == 'true'