chore(publish): add `--provenance` (#701)

This commit is contained in:
Antoine du Hamel 2025-04-09 17:48:07 +02:00 committed by GitHub
parent 0b94797f96
commit aefde28a63
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 6 additions and 4 deletions

View File

@ -29,6 +29,8 @@ jobs:
needs: release-please needs: release-please
if: ${{ needs.release-please.outputs.release_created }} if: ${{ needs.release-please.outputs.release_created }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
id-token: write
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
@ -48,10 +50,10 @@ jobs:
restore-keys: | restore-keys: |
${{runner.os}}-yarn- ${{runner.os}}-yarn-
- run: corepack yarn install --immutable
- name: Publish to the npm registry - name: Publish to the npm registry
run: | run: corepack yarn npm publish --provenance
corepack yarn install --immutable
corepack yarn npm publish
env: env:
YARN_NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} YARN_NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}

View File

@ -16,7 +16,7 @@
"./package.json": "./package.json" "./package.json": "./package.json"
}, },
"license": "MIT", "license": "MIT",
"packageManager": "yarn@4.6.0+sha512.5383cc12567a95f1d668fbe762dfe0075c595b4bfff433be478dbbe24e05251a8e8c3eb992a986667c1d53b6c3a9c85b8398c35a960587fbd9fa3a0915406728", "packageManager": "yarn@4.9.0+sha224.dce6c5df199861784bd9b0eecb2a228df97e3f18a02b1bb75ff98383",
"devDependencies": { "devDependencies": {
"@types/debug": "^4.1.5", "@types/debug": "^4.1.5",
"@types/node": "^20.4.6", "@types/node": "^20.4.6",