diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index de63ebd..6636704 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -7,6 +7,9 @@ on: jobs: publish-npm: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: - uses: actions/checkout@v3 - uses: actions/setup-node@v3 @@ -19,6 +22,4 @@ jobs: - run: npm version ${TAG_NAME} --git-tag-version=false env: TAG_NAME: ${{ github.event.release.tag_name }} - - run: npm whoami; npm publish - env: - NODE_AUTH_TOKEN: ${{secrets.npm_token}} + - run: npm publish --provenance