feat: switch npm releases to trusted publishing (OIDC) by styfle · Pull Request #1325 · vercel/ncc (original) (raw)
Navigation Menu
Appearance settings
- AI CODE CREATION
* GitHub CopilotWrite better code with AI
* GitHub Copilot appDirect agents from issue to merge
* MCP RegistryNewIntegrate external tools - DEVELOPER WORKFLOWS
* ActionsAutomate any workflow
* CodespacesInstant dev environments
* IssuesPlan and track work
* Code ReviewManage code changes - APPLICATION SECURITY
* GitHub Advanced SecurityFind and fix vulnerabilities
* Code securitySecure your code as you build
* Secret protectionStop leaks before they start - EXPLORE
* Why GitHub
* Documentation
* Blog
* Changelog
* Marketplace
- AI CODE CREATION
- BY COMPANY SIZE
* Enterprises
* Small and medium teams
* Startups
* Nonprofits - BY USE CASE
* App Modernization
* DevSecOps
* DevOps
* CI/CD
* View all use cases - BY INDUSTRY
* Healthcare
* Financial services
* Manufacturing
* Government
* View all industries
- BY COMPANY SIZE
- EXPLORE BY TOPIC
* AI
* Software Development
* DevOps
* Security
* View all topics - EXPLORE BY TYPE
* Customer stories
* Events & webinars
* Ebooks & reports
* Business insights
* GitHub Skills - SUPPORT & SERVICES
* Documentation
* Customer support
* Community forum
* Trust center
* Partners
- EXPLORE BY TOPIC
- COMMUNITY
* GitHub SponsorsFund open source developers - PROGRAMS
* Security Lab
* Maintainer Community
* Accelerator
* GitHub Stars
* Archive Program - REPOSITORIES
* Topics
* Trending
* Collections
- COMMUNITY
- Pricing
Provide feedback
We read every piece of feedback, and take your input very seriously.
Include my email address so I can be contacted
Saved searches
Use saved searches to filter your results more quickly
Appearance settings
Notifications You must be signed in to change notification settings
Additional navigation options
Merged
merged 1 commit into
mainfrom
May 27, 2026
ConversationCommits (1)ChecksFiles changed
Merged
feat: switch npm releases to trusted publishing (OIDC)#1325
merged 1 commit into
mainfrom
Conversation
styfle commented
•
edited
Loading
Copy link Copy Markdown
Member
Similar to vercel/nft#585
Configure a trusted publisher on npm:
- Package settings → Trusted publishing
- Provider: GitHub Actions
- Repository:
vercel/ncc - Workflow filename:
ci.yml
[feat: switch npm releases to trusted publishing (OIDC)](/vercel/ncc/pull/1325/commits/2536b40cbdf4d753ed33bf7a1d8bd5afba8967a6 "feat: switch npm releases to trusted publishing (OIDC)")
[2536b40](/vercel/ncc/pull/1325/commits/2536b40cbdf4d753ed33bf7a1d8bd5afba8967a6)
styfle marked this pull request as ready for review
styfle requested a review from ijjk
ijjk approved these changes May 27, 2026
styfleenabled auto-merge (squash)
styfle merged commit e00b2de into main
14 checks passed
styfle deleted the styfle/trusted-publishing branch
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters
[ Show hidden characters]({{ revealButtonHref }})
Sign up for free to join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers
ijjk ijjk approved these changes
Assignees
No one assigned
Labels
None yet
Projects
None yet
Milestone
No milestone
Development
Successfully merging this pull request may close these issues.