Skip to content

ci(release): add permissions for OIDC and npm provenance#185

Merged
gr2m merged 1 commit intomainfrom
ci/npm-provenance
Mar 21, 2026
Merged

ci(release): add permissions for OIDC and npm provenance#185
gr2m merged 1 commit intomainfrom
ci/npm-provenance

Conversation

@gr2m
Copy link
Owner

@gr2m gr2m commented Mar 21, 2026

Add permissions for OIDC, contents, pull-requests, and issues.

This enables npm provenance via trusted publishing — the NPM_TOKEN secret is no longer needed once the npm package is configured to trust GitHub Actions as a publisher.

Also updates actions/checkout and actions/setup-node to v4.

Add id-token, contents, pull-requests, and issues permissions.
Remove NPM_TOKEN in favor of trusted publishing via OIDC.
Update actions/checkout and actions/setup-node to v4.
@gr2m gr2m merged commit 49da025 into main Mar 21, 2026
4 checks passed
@gr2m gr2m deleted the ci/npm-provenance branch March 21, 2026 21:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant