Skip to content

Conversation

@tortmayr
Copy link
Contributor

@tortmayr tortmayr commented Oct 20, 2025

What it does

Setup a combined publish workflow for npm trusted publishing.
This avoid having to rotate the publish token every 90 days (new NPM policy).
For each package you can setup one trusted workflow for CI publishing (using OIDC)
image

Part of #1594

How to test

Publishing has to be verified after merging (publish.yml has to exist on master). So we need to merge and then fix potential issues afterwards.

Not really more to test here. Other things like push triggers have to be tested/reevaluated after merging.

Follow-ups

Changelog

  • This PR should be mentioned in the changelog
  • This PR introduces a breaking change (if yes, provide more details below for the changelog and the migration guide)

Copy link
Contributor

@martin-fleck-at martin-fleck-at left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@tortmayr tortmayr merged commit 3519b86 into master Oct 20, 2025
3 of 4 checks passed
@tortmayr tortmayr deleted the trusted-pub branch October 20, 2025 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants