We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents fe82bf1 + b0790d8 commit 63007bfCopy full SHA for 63007bf
1 file changed
.github/workflows/publish.yml
@@ -39,7 +39,9 @@ jobs:
39
${{ runner.os }}-yarn-
40
41
- name: Install Packages
42
- run: yarn install --frozen-lockfile --prefer-offline
+ # NOTE: The --ignore-scripts flag is required to prevent leakage of NPM_TOKEN value
43
+ # See https://github.com/actions/setup-node/blob/main/docs/advanced-usage.md#use-private-packages
44
+ run: yarn install --frozen-lockfile --prefer-offline --ignore-scripts
45
46
- name: Build
47
run: yarn prepack
@@ -52,7 +54,6 @@ jobs:
52
54
env:
53
55
NODE_ENV: "cicd"
56
NODE_AUTH_TOKEN: ${{secrets.npm_token}}
- NPM_TOKEN: ${{secrets.npm_token}}
57
GITHUB_TOKEN: ${{secrets.gh_token}}
58
GIT_AUTHOR_NAME: "autocloud-deploy-bot"
59
GIT_AUTHOR_EMAIL: "no-reply@autocloud.dev"
0 commit comments