Files
ponytail/.github/workflows/publish.yml
Emeriko 53a834fe6d ci: publish via npm trusted publishing (OIDC), drop NPM_TOKEN
Authenticate the release workflow through GitHub OIDC instead of a long-lived
npm token: no secret to leak or rotate, provenance attached automatically.
Upgrade npm on the runner since OIDC publishing needs npm >= 11.5.1 (Node 22
ships npm 10).
2026-06-24 02:56:32 +02:00

25 lines
575 B
YAML

name: publish
on:
push:
tags: ['v*']
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
# Trusted publishing (OIDC) needs npm >= 11.5.1; Node 22 ships npm 10.
- run: npm install -g npm@latest
# No token: id-token: write above lets npm authenticate via OIDC, and
# provenance is attached automatically. access set in publishConfig.
- run: npm publish