Skip to content

ci: publish with npm trusted publishing instead of NPM_TOKEN - #137

Merged
panz3r merged 1 commit into
mainfrom
ci/npm-trusted-publishing
Sep 29, 2026
Merged

panz3r merged 1 commit into
mainfrom
ci/npm-trusted-publishing

Conversation

@panz3r

@panz3r panz3r commented Sep 29, 2026

Copy link
Copy Markdown
Member

Every package in this repo now has an npm trusted publisher configured (forwardsoftware/gulp-plugins, release.yml), and the packages disallow token publishing.

  • npm publish authenticates through GitHub OIDC; drop NODE_AUTH_TOKEN: secrets.NPM_TOKEN.
  • Drop --provenance (automatic with trusted publishing) and --access public (only needed for the first publish of a scoped package).

Same publish step as react-auth and react-native-toolbox. Verified end to end with gulp-sharp 1.0.3, which was published via OIDC with provenance.

@panz3r
panz3r merged commit 5137383 into main Sep 29, 2026
10 checks passed
@panz3r
panz3r deleted the ci/npm-trusted-publishing branch September 29, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant