Skip to content

Update npm publish workflow to use OIDC#16

Merged
timwright12 merged 1 commit intomainfrom
update/npm-trusted-provider
Nov 20, 2025
Merged

Update npm publish workflow to use OIDC#16
timwright12 merged 1 commit intomainfrom
update/npm-trusted-provider

Conversation

@timwright12
Copy link
Copy Markdown
Contributor

We got a notice from npm that we need to migrate off tokens into OIDC trusted publishers. This is lifting action code from the documentation: https://docs.npmjs.com/trusted-publishers#github-actions-configuration

Security Update: npm classic token creation is now disabled. Existing classic tokens will be revoked on December 9, 2025. Migrate to trusted publishing or granular access tokens to avoid disruption. Learn more

Trusted published setup:

Screenshot 2025-11-20 at 12 58 35 PM

Steps to Test

I think we'll just have to run it and see

@timwright12
Copy link
Copy Markdown
Contributor Author

@AnJuHyppolite if you'd like to put eyes on this

@timwright12 timwright12 merged commit f9dd36f into main Nov 20, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant