Skip to content

Conversation

kqito
Copy link
Owner

@kqito kqito commented Aug 20, 2025

This PR is a critical fix to enable NPM's Provenance feature.
The id-token: write permission allows GitHub Actions to generate OIDC tokens and attach signed attestations to NPM packages. This enables package consumers to verify that the package was genuinely built from this repository using this specific workflow.

@kqito kqito force-pushed the fix-permission-for-provenance-release branch from 97c05ab to b35a9a3 Compare August 20, 2025 12:37
@kqito kqito self-assigned this Aug 20, 2025
@kqito kqito merged commit 880ecd8 into main Aug 20, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant