Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@kqito
Copy link
Owner

@kqito kqito commented Aug 20, 2025

This PR adds the NPM_CONFIG_PROVENANCE environment variable to the npm-publish workflow.

By enabling NPM Provenance, packages published through GitHub Actions will include attestation metadata that proves where and how the package was built. This enhancement improves supply chain security by allowing package consumers to verify that the published package was indeed built by the official GitHub Actions workflow, providing greater transparency and trust in the distribution process.

@kqito kqito merged commit d51f567 into main Aug 20, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants