Use NPM Trusted Publishers over token

due to security changes being enacted next month by npm
pull/2239/head
Michael Telatynski 1 month ago
parent 9d063c8d2d
commit e4ab0cd9c8
No known key found for this signature in database
GPG Key ID: A2B008A5F49F5D0D

@ -12,6 +12,9 @@ jobs:
defaults:
run:
working-directory: packages/npm
permissions:
contents: read
id-token: write
steps:
- name: 🧮 Checkout code
uses: actions/checkout@v4
@ -33,10 +36,4 @@ jobs:
VERSION: ${{ github.event.release.tag_name }}.0
- name: 🚀 Publish to npm
id: npm-publish
uses: JS-DevTools/npm-publish@19c28f1ef146469e409470805ea4279d47c3d35c # v3.1.1
with:
token: ${{ secrets.NPM_TOKEN }}
package: packages/npm
access: public
ignore-scripts: false
run: npm publish --provenance --access public --tag latest

Loading…
Cancel
Save