Skip to content

Publish npm releases with trusted OIDC - #36

Merged
ostapondo merged 1 commit into
mainfrom
feature/npm-trusted-publishing
Aug 28, 2026
Merged

ostapondo merged 1 commit into
mainfrom
feature/npm-trusted-publishing

Conversation

@ostapondo

Copy link
Copy Markdown
Owner

Summary

  • remove the obsolete npm token from the release workflow
  • rely on the package-scoped npm Trusted Publisher configured for ostapondo/rescueloop and release.yml
  • keep GitHub OIDC provenance and the GitHub Packages mirror unchanged

Validation

  • successful rescueloop@0.0.2 publish through npm Trusted Publishing
  • successful GitHub Packages mirror publish
  • node scripts/sync-version.mjs --check 0.0.2
  • git diff --check

MCP impact

No MCP changes; this only narrows release authentication.

@ostapondo
ostapondo merged commit b4f374d into main Aug 28, 2026
2 checks passed
@ostapondo
ostapondo deleted the feature/npm-trusted-publishing branch August 28, 2026 17:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant