Skip to content

[Feature Request]: Trusted publishing for npm packages #1725

@btea

Description

@btea

What should be improved?

https://docs.npmjs.com/trusted-publishers

Describe the solution you would like

e18e/ecosystem-issues#201

Possible alternatives

No response

Additional context

Recently, npm dependency packages have been frequently attacked. To reduce the risk of token leakage., it is recommended to remove the npm token and use OIDC for publishing.

Are you willing to work on this?

  • Yes, I would like to help

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions