Skip to content

Publish to npm with trusted publishing - #17

Merged
0thernet merged 1 commit into
mainfrom
decisions/20260929-publishing
Sep 29, 2026
Merged

0thernet merged 1 commit into
mainfrom
decisions/20260929-publishing

Conversation

@0thernet

Copy link
Copy Markdown
Member

Adds a release job that publishes to npm through GitHub Actions OIDC trusted publishing. No registry token is stored and no one approves a release. Nothing is published by this change.

The job does nothing until the one-time registry setup in CONTRIBUTING.md is done: npm only lets trusted publishing update a package that already exists.

🤖 Generated with Claude Code

Add a release job that publishes through GitHub Actions OIDC, with no
stored registry token and no approval per release. Document the one-time
registry setup a maintainer does before the job can publish.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@0thernet
0thernet enabled auto-merge (squash) September 29, 2026 16:20
@0thernet
0thernet merged commit 99a7319 into main Sep 29, 2026
5 checks passed
@0thernet
0thernet deleted the decisions/20260929-publishing branch September 29, 2026 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant