All tags

#devops

1 post tagged with devops.

  1. The npm Package Publishing Mental Model

    Things you need to do for npm trusted publishing to work, and the secure mental model behind it: OIDC identity chain, provenance attestation, and a complete GitHub Actions workflow.

    14 min