Skip to content

ci(release): publish from the protected npm-publish environment - #25

Merged
DuncanFaulkner merged 1 commit into
mainfrom
ci/release-environment
Sep 30, 2026
Merged

DuncanFaulkner merged 1 commit into
mainfrom
ci/release-environment

Conversation

@DuncanFaulkner

Copy link
Copy Markdown
Contributor

Every release run (dry runs too) now pauses for a required reviewer (@DuncanFaulkner) in the Actions UI, and only runs from main. Part of locking down the public repo (ruleset on main, squash-only, fork-PR approval, secret scanning, Dependabot alerts).

Optional follow-up on npmjs.com: pin the trusted publisher to environment npm-publish, so only this environment can publish.

🤖 Generated with Claude Code

…ment

Each release (dry runs too) now waits for a required reviewer's approval and
only runs from main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@DuncanFaulkner
DuncanFaulkner merged commit 0d9b59d into main Sep 30, 2026
1 check passed
@DuncanFaulkner
DuncanFaulkner deleted the ci/release-environment branch September 30, 2026 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant