From d074a13501fce3e2474d845ca8ea411ddc23a617 Mon Sep 17 00:00:00 2001 From: Mattias Buelens Date: Thu, 4 Dec 2025 16:12:31 +0100 Subject: [PATCH] Use trusted publishing --- .github/workflows/release.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 69cc21c4..d3bf7cc2 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -8,6 +8,9 @@ jobs: release: name: Release runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: - name: Checkout Repo uses: actions/checkout@v4 @@ -30,5 +33,4 @@ jobs: createGithubReleases: true env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + NPM_CONFIG_PROVENANCE: true