Skip to content

fix: switch to npm trusted publishing (OIDC)#12

Merged
c99e merged 2 commits intomainfrom
fix/trusted-publishing
Mar 27, 2026
Merged

fix: switch to npm trusted publishing (OIDC)#12
c99e merged 2 commits intomainfrom
fix/trusted-publishing

Conversation

@c99e
Copy link
Copy Markdown
Owner

@c99e c99e commented Mar 27, 2026

Replaces NPM_TOKEN secret with npm Trusted Publishing via OIDC. No tokens or OTP needed.

Requires npm-side setup: Add a trusted publisher on npmjs.com/package/shopq/access with repo c-99-e/shopq, workflow publish.yml, environment NPM.

c99e added 2 commits March 28, 2026 02:43
- Add id-token: write permission for OIDC
- Use --provenance --access public instead of NPM_TOKEN
- No secrets or OTP needed
@c99e c99e merged commit 38bdb9c into main Mar 27, 2026
4 checks passed
@c99e c99e deleted the fix/trusted-publishing branch March 27, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant