From f19d04952e703824e6e1a5fcce538a02f4044939 Mon Sep 17 00:00:00 2001 From: drewstone Date: Tue, 2 Jun 2026 12:41:56 +0300 Subject: [PATCH] ci: add npm provenance attestation to release publish --- .github/workflows/publish.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 717e337..2787d49 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -77,7 +77,7 @@ jobs: if npm view "$NAME@$VERSION" version >/dev/null 2>&1; then echo "$NAME@$VERSION already on registry; skipping publish" else - pnpm publish --no-git-checks --access public + pnpm publish --no-git-checks --access public --provenance fi env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}