Repository navigation
v1.0.1
Published by the check, not by hand.
No source file changed since v1.0.0. What changed is how this version was built, and what it can now prove about itself.
npx @luan-afonso/firstmate startProvenance
v1.0.1 carries a SLSA v1 provenance attestation. It says which repository, which tag and which workflow produced the tarball:
repository : https://github.com/luanAfons0/FirstMate
ref : refs/tags/v1.0.1
workflow : .github/workflows/release.yml
subject : pkg:npm/@luan-afonso/firstmate@1.0.1
Check it yourself:
npm install @luan-afonso/firstmate
npm audit signaturesv1.0.0 was published from a laptop and carries none, which is the whole reason this version exists.
No secret to keep
npm accepts GitHub Actions as a trusted publisher over OpenID Connect, so the release job asks for an identity token minted for that one run and expiring in minutes. There is no NPM_TOKEN in this repository, and none to leak or rotate.
The job refuses a tag that disagrees with package.json, checks the types and runs the whole suite before it publishes, so a broken release cannot leave the machine.
How a release is cut is written down in CONTRIBUTING.md, so it is not one person's knowledge.
Node 24 or newer. MIT. The command is still firstmate.