Skip to content

ci(release): publish toolkits with npm Trusted Publisher - #12

Merged
mrgoonie merged 1 commit into
mainfrom
codex/npm-trusted-publisher
Sep 12, 2026
Merged

mrgoonie merged 1 commit into
mainfrom
codex/npm-trusted-publisher

Conversation

@mrgoonie

Copy link
Copy Markdown
Contributor

Summary

Replace token-based npm publication with GitHub OIDC Trusted Publishing. Tagged releases validate main ancestry and package versions, build/test/type-check, pack workspace dependencies, and publish with npm 11.19.0 on Node 24. Manual runs produce tarballs for initial package bootstrap without publishing.

Add repository metadata required for provenance and restrict package contents to dist/bin. Document the per-package trust configuration and first-publish procedure.

Validation

  • 113 tests pass.
  • All three package builds and type-checks pass.
  • git diff --check passes.
  • Registry trust and a live tagged release will be verified after the initial package bootstrap.

@mrgoonie
mrgoonie merged commit 3a7772e into main Sep 12, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant