Skip to content

ci(cd): make provenance publishing explicit#551

Merged
Fdawgs merged 1 commit intomainfrom
ci/cd
Feb 25, 2026
Merged

ci(cd): make provenance publishing explicit#551
Fdawgs merged 1 commit intomainfrom
ci/cd

Conversation

@Fdawgs
Copy link
Owner

@Fdawgs Fdawgs commented Feb 25, 2026

Security tooling can't tell i'm using npm's oidc for provenance, so add this back in.

Checklist

Security tooling can't tell i'm using npm's oidc for provenance, so add this back in.
Copilot AI review requested due to automatic review settings February 25, 2026 12:31
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the CD workflow so npm provenance is explicitly requested during publishes, making the use of npm’s OIDC/trusted publishing visible to security tooling.

Changes:

  • Add --provenance to the npmjs.org publish command in the CD workflow.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@Fdawgs Fdawgs merged commit 0d461ed into main Feb 25, 2026
21 checks passed
@Fdawgs Fdawgs deleted the ci/cd branch February 25, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants