Skip to content

Conversation

@bedrich-schindler
Copy link
Contributor

Closes #687

This requires to add thrust published on npmjs.com before running
`publish_package_to_npm` job. `NPM_PUBLISH_TOKEN` secret can be
then removed from repository settings.
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds provenance statement generation to the npm publishing process by adding the --provenance flag to the npm publish command. Provenance provides transparency about how and where the package was built, enhancing supply chain security.

  • Adds --provenance flag to the npm publish command to generate and publish attestations

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Base automatically changed from maintenance/685 to master December 23, 2025 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants