diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 4f4cd9c..d985b39 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -6,6 +6,7 @@ on: permissions: contents: read + id-token: write jobs: publish-npm: @@ -24,6 +25,4 @@ jobs: npm version ${TAG_NAME} --git-tag-version=false env: TAG_NAME: ${{github.event.release.tag_name}} - - run: npm whoami; npm --ignore-scripts publish - env: - NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} + - run: npm --ignore-scripts publish --provenance