-
Notifications
You must be signed in to change notification settings - Fork 199
ci: publish npm package with trusted publisher #972
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
No longer use a token to increase security.
WalkthroughGitHub Actions workflow for npm package publishing has been updated to replace token-based authentication with OIDC trusted publisher setup. The NODE_AUTH_TOKEN environment variable was removed, and comments were updated to reflect that npm provenance will now rely on trusted publisher configuration instead of explicit token credentials. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~5 minutes
Pre-merge checks and finishing touches❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✨ Finishing touches🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: CodeRabbit UI Review profile: CHILL Plan: Pro 📒 Files selected for processing (1)
🧰 Additional context used🧠 Learnings (1)📓 Common learnings⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
🔇 Additional comments (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|



No longer use a token to increase security.
Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.