Skip to content

ci(cd): make provenance publishing explicit#387

Merged
Fdawgs merged 1 commit intomainfrom
ci/cd
Feb 25, 2026
Merged

ci(cd): make provenance publishing explicit#387
Fdawgs merged 1 commit intomainfrom
ci/cd

Conversation

@Fdawgs
Copy link
Copy Markdown
Owner

@Fdawgs Fdawgs commented Feb 25, 2026

Security tooling can't tell i'm using npm's oidc for provenance, so add this back in.

Checklist

Security tooling can't tell i'm using npm's oidc for provenance, so add this back in.
Copilot AI review requested due to automatic review settings February 25, 2026 12:30
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds the --provenance flag to the NPM publish command to make OIDC-based provenance publishing explicit, ensuring security tooling can properly detect and verify the provenance attestations.

Changes:

  • Added --provenance flag to the npm publish command in the NPM publishing job to enable explicit OIDC provenance attestations

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@Fdawgs Fdawgs merged commit b7e4b74 into main Feb 25, 2026
21 checks passed
@Fdawgs Fdawgs deleted the ci/cd branch February 25, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants