set up "trusted publishers" for releasing to npm#358
Closed
Conversation
3c65340 to
68c5bd1
Compare
kaisen
requested changes
Oct 27, 2025
.github/workflows/release.yml
Outdated
Comment on lines
7
to
8
| permissions: | ||
| id-token: write # required for publishing |
Member
There was a problem hiding this comment.
from the linked PR in the PR description, it seems that permissions should be a key under publish-npm below? i think this is better so the id-token permission is limited to only the publish step
kaisen
approved these changes
Oct 27, 2025
Author
|
this won't work because of the OIDC feature being present only in yarnv2 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I've set things up in the npmjs settings for this package, and YARN should have support for the OIDC workflow in yarnpkg/berry#6898.
How can we reasonably test this? I absolutely have no idea other than trying to release a new version of the package after shipping this change.