Skip to content

Use npm OIDC trusted publishing - #29

Merged
kcsfelty merged 1 commit into
mainfrom
agent/oidc-only-publishing
Jul 20, 2026
Merged

Use npm OIDC trusted publishing#29
kcsfelty merged 1 commit into
mainfrom
agent/oidc-only-publishing

Conversation

@kcsfelty

Copy link
Copy Markdown
Collaborator

Summary

  • remove the temporary NPM_TOKEN fallback from the release workflow
  • publish with npm trusted publishing (GitHub OIDC) only
  • disable dependency caching in the release job
  • prepare the v0.3.1 verification release and update release documentation

The npm trusted publisher is configured for gnolith/diamond, workflow release.yml, environment release, and permission npm publish.

Validation

  • npm run format
  • npm run check (113 tests)
  • npm run conformance (490/490)
  • npm run benchmark:check
  • npm run benchmark:storage:check
  • GITHUB_REPOSITORY_VISIBILITY=public npm run release:check -- v0.3.1
  • git diff --check

@kcsfelty
kcsfelty marked this pull request as ready for review July 20, 2026 21:29
@kcsfelty
kcsfelty merged commit d6d470d into main Jul 20, 2026
10 checks passed
@kcsfelty
kcsfelty deleted the agent/oidc-only-publishing branch July 20, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant