Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Support OIDC publishing ("trusted publishing") #9812

@lishaduck

Description

@lishaduck

Contribution

Describe the user story

Trusted publishing is an important security feature that prevents leaking long-lived publishing tokens from workflows. The npmjs registry supports it, so it's important that it works throughout the ecosystem.

Describe the solution you'd like

Now that npmjs.com & the npm client support OIDC publishing, the pnpm client should follow suit.

Describe the drawbacks of your solution

  • Requires implementation, maintenance, etc
  • Locks publishers into GitHub/GitLab

Describe alternatives you've considered

Don't implement it-which, for better and for worse, will look insecure on our part, especially once Yarn or Bun implement it.

Related

#8897 (comment)

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions