feat: add npm provenance attestation and stable release workflow (#77)

- Add --provenance flag to npm publish commands for supply chain security
- Create publish-stable.yml workflow for @latest releases
- Fixes missing provenance badges on npm (issue #5547)
This commit is contained in:
Marius
2026-02-02 16:35:23 +01:00
committed by GitHub
parent 6ecb406a32
commit 41539aefa2
2 changed files with 79 additions and 2 deletions
+2 -2
View File
@@ -45,12 +45,12 @@ const tasks = Object.entries(binaries).map(async ([name]) => {
}
await $`bun pm pack`.cwd(`./dist/${name}`)
for (const tag of tags) {
await $`npm publish *.tgz --access public --tag ${tag}`.cwd(`./dist/${name}`)
await $`npm publish *.tgz --access public --tag ${tag} --provenance`.cwd(`./dist/${name}`)
}
})
await Promise.all(tasks)
for (const tag of tags) {
await $`cd ./dist/${pkg.name} && bun pm pack && npm publish *.tgz --access public --tag ${tag}`
await $`cd ./dist/${pkg.name} && bun pm pack && npm publish *.tgz --access public --tag ${tag} --provenance`
}
if (!Script.preview) {