Skip to content

Switch NPM publishing to trusted publishing with provenance - #6405

Merged
kevin-brown merged 1 commit into
developfrom
use-npm-trusted-publishing
May 26, 2026
Merged

kevin-brown merged 1 commit into
developfrom
use-npm-trusted-publishing

Conversation

@kevin-brown

Copy link
Copy Markdown
Member

This pull request includes a

  • Bug fix
  • New feature
  • Translation
  • Maintenance

The following changes were made

  • Add id-token: write permission so the job can obtain an OIDC token from GitHub, which NPM uses to authenticate the publish request
  • Add contents: read as explicit least-privilege for the checkout step
  • Pass --provenance to npm publish to attach a signed provenance attestation linking the published package to this workflow run
  • Pass --access public to ensure the package is published as public

Replace the long-lived NPM_TOKEN secret with OIDC-based trusted
publishing. This removes the need to store and rotate a static token in
repository secrets.

- Add id-token: write permission so the job can obtain an OIDC token
  from GitHub, which NPM uses to authenticate the publish request
- Add contents: read as explicit least-privilege for the checkout step
- Pass --provenance to npm publish to attach a signed provenance
  attestation linking the published package to this workflow run
- Pass --access public to ensure the package is published as public

Trusted publishing must also be enabled on the npmjs.com package
settings page by adding this repository and workflow as a trusted
publisher.
@kevin-brown
kevin-brown enabled auto-merge (squash) May 26, 2026 19:46
@kevin-brown
kevin-brown merged commit 7fddd0b into develop May 26, 2026
6 checks passed
@kevin-brown
kevin-brown deleted the use-npm-trusted-publishing branch May 26, 2026 19:47
kevin-brown added a commit that referenced this pull request May 26, 2026
- Remove '(unreleased)' marker from the 4.1.0 heading
- Add new features: jQuery 4.0.0 support (#6332), originalEvent in
  close trigger args (#6079)
- Add bug fixes: placeholder misalignment (#6277), RTL choice remove
  button (#6257), digit-only data-placeholder (#6297), AJAX unselection
  with non-string IDs (#6241, #6335), optgroup child string coercion (#6338)
- Add translations: lb (#6131), ug (#6166), ar (#6175), zh-TW (#6157),
  id (#6153), tr (#6123), ro (#6190), de/es/fr/pt/pt-BR (#6132),
  pl (#6097, #6377), nb (#6213), fa (#6258), nl (#6269), pt-BR typo
  (#6200), missing bs/ca/da/fi strings (#6305)
- Add miscellaneous: native DOM replacements for jQuery attr/removeAttr
  (#6227, #6228), classList.add (#6229), jQuery removal from Utils and
  Translation (#6233), prop() removal (#6289), NPM trusted publishing
  (#6405)
maxwellfet928 pushed a commit to maxwellfet928/select2 that referenced this pull request Jun 8, 2026
…6405)

Replace the long-lived NPM_TOKEN secret with OIDC-based trusted
publishing. This removes the need to store and rotate a static token in
repository secrets.

- Add id-token: write permission so the job can obtain an OIDC token
  from GitHub, which NPM uses to authenticate the publish request
- Add contents: read as explicit least-privilege for the checkout step
- Pass --provenance to npm publish to attach a signed provenance
  attestation linking the published package to this workflow run
- Pass --access public to ensure the package is published as public

Trusted publishing must also be enabled on the npmjs.com package
settings page by adding this repository and workflow as a trusted
publisher.
maxwellfet928 pushed a commit to maxwellfet928/select2 that referenced this pull request Jun 8, 2026
- Remove '(unreleased)' marker from the 4.1.0 heading
- Add new features: jQuery 4.0.0 support (select2#6332), originalEvent in
  close trigger args (select2#6079)
- Add bug fixes: placeholder misalignment (select2#6277), RTL choice remove
  button (select2#6257), digit-only data-placeholder (select2#6297), AJAX unselection
  with non-string IDs (select2#6241, select2#6335), optgroup child string coercion (select2#6338)
- Add translations: lb (select2#6131), ug (select2#6166), ar (select2#6175), zh-TW (select2#6157),
  id (select2#6153), tr (select2#6123), ro (select2#6190), de/es/fr/pt/pt-BR (select2#6132),
  pl (select2#6097, select2#6377), nb (select2#6213), fa (select2#6258), nl (select2#6269), pt-BR typo
  (select2#6200), missing bs/ca/da/fi strings (select2#6305)
- Add miscellaneous: native DOM replacements for jQuery attr/removeAttr
  (select2#6227, select2#6228), classList.add (select2#6229), jQuery removal from Utils and
  Translation (select2#6233), prop() removal (select2#6289), NPM trusted publishing
  (select2#6405)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Sponsor
SponsoredKunjungi sekarang
Promo