Skip to content

Conversation

matthewp
Copy link
Contributor

Changes

  • Updates the release.yml to use oidc.

Testing

N/A

Docs

N/A

Copy link

changeset-bot bot commented Oct 17, 2025

⚠️ No Changeset found

Latest commit: 63b7370

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions github-actions bot added the 🚨 action Modifies GitHub Actions label Oct 17, 2025
@matthewp
Copy link
Contributor Author

@HiDeoo @delucis updated

Copy link
Member

@HiDeoo HiDeoo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great to me now and matches what I've been doing so far 👍

I guess a remaining question could be whether this needs a changeset or not, is this a change we may want to inform users about?

@matthewp
Copy link
Contributor Author

No, this is a change to how we publish packages, it shouldn't cause users to have to upgrade any packages.

@HiDeoo
Copy link
Member

HiDeoo commented Oct 17, 2025

Yeah, was looking at what we did when we added provenance by curiosity, it was a patch to all packages.

Also looking at that old change, we could technically also remove the "provenance": true from all package.json if we wanted.

@delucis
Copy link
Member

delucis commented Oct 17, 2025

I’d be +1 on making it a patch for all packages: it would ensure securely published versions of everything go out now rather than only being published next time there’s a change to a package.

Users wouldn’t have to upgrade, but they could if they wanted.

@matthewp matthewp merged commit 9e260ec into main Oct 17, 2025
19 checks passed
@matthewp matthewp deleted the oidc branch October 17, 2025 18:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🚨 action Modifies GitHub Actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants