Commit a54c7ff

Anton Golub <antongolub@antongolub.com>
2024-05-28 09:06:24
ci: enable npm provenance for dev publish (#830)
1 parent b3fcad2
Changed files (1)
.github
.github/workflows/dev-publish.yml
@@ -6,6 +6,12 @@ on:
 jobs:
   publish:
     runs-on: ubuntu-latest
+    permissions:
+      checks: read
+      statuses: write
+      contents: write
+      packages: write
+      id-token: write
     steps:
       - uses: actions/checkout@v4
       - uses: actions/setup-node@v4
@@ -20,4 +26,4 @@ jobs:
           AUTH_TOKEN: ${{ secrets.AUTH_TOKEN }}
       - run: |
           npm version $(node --eval="process.stdout.write(require('./package.json').version)")-dev.$(git rev-parse --short HEAD) --no-git-tag-version
-          npm publish --no-git-tag-version --tag dev
+          npm publish --provenance --access=public --no-git-tag-version --tag dev