Trusted Publishing becomes the release path - #19
Closed
ohansFavour wants to merge 1 commit into
Closed
ohansFavour wants to merge 1 commit into
ohansFavour wants to merge 1 commit into
Conversation
A pushed v* tag publishes via npm Trusted Publishing (OIDC, npm >= 11.5.1 installed in the job) with provenance attestation. No long-lived token exists anywhere; until the Trusted Publisher is configured on npmjs.com, a pushed tag still fails closed at authentication. The SECURITY.md constraint and the threat model's supply-chain paragraph are superseded accordingly, dating the manual era through 0.2.4 and keeping the deterministic-build verification path. Merge gate: configure the Trusted Publisher on the npm side and re-enable the workflow before merging, so the docs are true the moment they land.
|
Closing without merging: releases stay manual for now, so the dormant workflow and the published security docs remain accurate as-is. |
Member
Author
|
Owner decision: publishing stays manual for now; Trusted Publishing remains deferred. The workflow and docs on main stay dormant/true as-is. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explored switching releases to npm Trusted Publishing (OIDC + provenance from the pinned workflow). Closed without merging: releases stay manual for now, so the dormant workflow and the published security docs remain accurate as-is.