ci: switch npm publish to trusted publishing (OIDC)#25
Conversation
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
Disabled knowledge base sources:
📝 WalkthroughWalkthroughThe CI workflow's npm publishing step was reconfigured to use provenance-based authentication. The workflow permissions were shifted from Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Poem
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
O que muda
NPM_TOKENpor Trusted Publishing (OIDC)id-token: write(necessário para OIDC)packages: write(não necessário para npm registry)--provenancenonpm publishpara gerar provenance statementsPor quê
Trusted Publishing é mais seguro que tokens de longa duração:
Setup necessário após merge
Para cada pacote
@arvoretech/*no npm:arvoreeducacao, repo=arvore-mcp-servers, workflow=ci.ymlSummary by CodeRabbit