From 57deece36ea58ea4f5dd9520fe924557b01973e1 Mon Sep 17 00:00:00 2001 From: Jozef Izso Date: Fri, 24 Oct 2025 15:34:43 +0200 Subject: [PATCH] Use trusted publishing to npmjs.org in `release.yml` workflow --- .github/workflows/release.yml | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8461ae7..2d95749 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -4,10 +4,18 @@ on: release: types: [published] +permissions: + id-token: write + contents: read + jobs: publish: + environment: + name: production + url: https://www.npmjs.com/package/@slidoapp/markdown-cli + runs-on: ubuntu-latest - + steps: - uses: actions/checkout@v5 @@ -19,5 +27,3 @@ jobs: - run: npm ci - run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NODE_AUTH_TOKEN }}