Skip to content

ci(release): add permissions for OIDC and npm provenance#1881

Open
gr2m wants to merge 1 commit into
mainfrom
ci/npm-provenance
Open

ci(release): add permissions for OIDC and npm provenance#1881
gr2m wants to merge 1 commit into
mainfrom
ci/npm-provenance

Conversation

@gr2m
Copy link
Copy Markdown
Collaborator

@gr2m gr2m commented Mar 21, 2026

Enables npm provenance via OIDC trusted publishing. Removes NPM_TOKEN dependency — the id-token: write permission handles authentication automatically.

See gr2m/semantic-release-plugin-update-version-in-files#62 for reference.

rsbasic

This comment was marked as spam.

@gr2m
Copy link
Copy Markdown
Collaborator Author

gr2m commented Apr 22, 2026

@rsbasic please stop AI generated spamming. It's not appreciated. It will get you blocked, or suspended.

@gr2m
Copy link
Copy Markdown
Collaborator Author

gr2m commented Apr 22, 2026

@TimothyGu @bitinn @jimmywarting can one of you enable provenance at https://www.npmjs.com/package/node-fetch/access. This will let us invalidate and remove the NPM_TOKEN configured in this repo and remove an vector for a supply chain attack.

Copy link
Copy Markdown
Member

@Richienb Richienb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tysm!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants