-
Notifications
You must be signed in to change notification settings - Fork 9
ci(publish-to-npm): Add provenance flag to npm publish
and update permissions.
#73
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
WalkthroughThe update introduces support for provenance in the npm publishing process. In the GitHub Actions workflow, a new permissions setting is added with Changes
Sequence Diagram(s)sequenceDiagram
participant Runner as GitHub Actions Runner
participant Job as publish-to-npm Job
participant Registry as npm Registry
Runner->>Job: Trigger publish-to-npm job
Job->>Job: Set permissions (id-token: "write")
Job->>Job: Run release script (npm publish --provenance)
Job->>Registry: Publish package with provenance info
Registry-->>Job: Return publish confirmation
📜 Recent review detailsConfiguration used: CodeRabbit UI 📒 Files selected for processing (2)
⏰ Context from checks skipped due to timeout of 90000ms (2)
🔇 Additional comments (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
Description
This PR updates the release script in
package.json
to include the--provenance
flag when publishing the package. Additionally, the GitHub Actions workflowpublish-to-npm.yml
has been updated to:These changes ensure secure and traceable package publishing.
Checklist
breaking change.
Validation performed
--dry-run
) ofnpm publish
with the--provenance
flag to ensure no issues arise:npm publish --dry-run --provenance
.Summary by CodeRabbit