Skip to content

Commit 8ff829b

Browse files
feat(ci): npm publish via OIDC trusted publishing (#4)
Release-triggered publish (plus workflow_dispatch backfill) with provenance, no tokens. Requires the trusted publisher configured on npmjs.com for this repo + publish.yml.
1 parent 26b9332 commit 8ff829b

1 file changed

Lines changed: 47 additions & 0 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
name: Publish to npm
2+
3+
on:
4+
release:
5+
types:
6+
- published
7+
# Manual backfill (e.g. publishing an existing tag after wiring OIDC).
8+
workflow_dispatch:
9+
10+
permissions:
11+
contents: read
12+
id-token: write
13+
14+
concurrency:
15+
group: npm-${{ github.event.release.tag_name || github.run_id }}
16+
cancel-in-progress: false
17+
18+
jobs:
19+
publish:
20+
name: publish
21+
runs-on: ubuntu-latest
22+
timeout-minutes: 15
23+
24+
steps:
25+
- name: Checkout
26+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
27+
28+
- name: Setup Node.js
29+
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
30+
with:
31+
node-version: 24
32+
registry-url: https://registry.npmjs.org/
33+
package-manager-cache: false
34+
35+
- name: Install dependencies
36+
run: npm ci
37+
38+
- name: Verify build and tests
39+
run: npm test
40+
41+
- name: Verify package contents
42+
run: npm pack --dry-run
43+
44+
# OIDC trusted publishing (no tokens): requires the trusted publisher
45+
# configured on npmjs.com for this repo + publish.yml workflow.
46+
- name: Publish with provenance
47+
run: npm publish --access public --provenance

0 commit comments

Comments
 (0)