Skip to content

Trusted Publishing becomes the release path - #19

Closed
ohansFavour wants to merge 1 commit into
mainfrom
feat/trusted-publishing
Closed

ohansFavour wants to merge 1 commit into
mainfrom
feat/trusted-publishing

Conversation

@ohansFavour

@ohansFavour ohansFavour commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Explored switching releases to npm Trusted Publishing (OIDC + provenance from the pinned workflow). Closed without merging: releases stay manual for now, so the dormant workflow and the published security docs remain accurate as-is.

A pushed v* tag publishes via npm Trusted Publishing (OIDC, npm >=
11.5.1 installed in the job) with provenance attestation. No long-lived
token exists anywhere; until the Trusted Publisher is configured on
npmjs.com, a pushed tag still fails closed at authentication. The
SECURITY.md constraint and the threat model's supply-chain paragraph
are superseded accordingly, dating the manual era through 0.2.4 and
keeping the deterministic-build verification path.

Merge gate: configure the Trusted Publisher on the npm side and
re-enable the workflow before merging, so the docs are true the moment
they land.
@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Closing without merging: releases stay manual for now, so the dormant workflow and the published security docs remain accurate as-is.

@ohansFavour

Copy link
Copy Markdown
Member Author

Owner decision: publishing stays manual for now; Trusted Publishing remains deferred. The workflow and docs on main stay dormant/true as-is.

@ohansFavour
ohansFavour deleted the feat/trusted-publishing branch September 17, 2026 02:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant