All tags

#github-actions

1 post tagged with github-actions.

  1. The npm Package Publishing Mental Model

    Things you need to do for npm trusted publishing to work, and the secure mental model behind it: OIDC identity chain, provenance attestation, and a complete GitHub Actions workflow.

    14 min