Details
-
Task
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Fixed
-
None
-
None
Description
Releases are currently published by hand with a maintainer account and token.
Goal is to publish it from github directly with npm "Trusted Publisher" fonctionnality.
This will add a "Provenance" section indicating all details on version
packaging will be done in 2 steps :
- when commiting a new git tag version, package will be published in "staging" (can be run manually too)
- publisher will need a manual npm stage approve to released
With trusted publishing every published version is signed and verified by npm audit signatures. The same workflow identity can later sign additional artifacts, such as an SBOM