Skip to content

ci: add read-only npm publisher audit - #21

Merged
routeplane-ops merged 1 commit into
mainfrom
ci/npm-trust-audit
Aug 13, 2026
Merged

ci: add read-only npm publisher audit#21
routeplane-ops merged 1 commit into
mainfrom
ci/npm-trust-audit

Conversation

@routeplane-ops

Copy link
Copy Markdown
Collaborator

Summary

Add a manually triggered, read-only audit for the three npm Trusted Publisher records. It emits only provider claims and permissions, never configuration IDs or credentials.

Security

  • no repository checkout or untrusted code execution
  • no GitHub token permissions
  • npm credential scoped to the single read step
  • fixed registry endpoint and fixed package names
  • npm version asserted before use

Validation

  • actionlint .github/workflows/npm-trust-audit.yml
  • zizmor .github/workflows/npm-trust-audit.yml
  • git diff --check

@routeplane-ops
routeplane-ops merged commit 2fb35d1 into main Aug 13, 2026
1 check passed
@routeplane-ops
routeplane-ops deleted the ci/npm-trust-audit branch August 13, 2026 17:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants