Skip to content

Commit 3971c0b

Browse files
authoredOct 1, 2024··
feat: generating provenance statements (#2771)
* feat: generating provenance statements * Update publish-npm.sh
1 parent 25e4cb1 commit 3971c0b

File tree

2 files changed

+7
-4
lines changed

2 files changed

+7
-4
lines changed
 

‎.github/scripts/publish-npm.sh

+5-4
Original file line numberDiff line numberDiff line change
@@ -57,8 +57,9 @@ do
5757
echo "Could not authenticate with $REGISTRY"
5858
exit 1
5959
fi
60-
npm publish --tag "$TAG" db-ui-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz
61-
npm publish --tag "$TAG" db-ui-ngx-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz
62-
npm publish --tag "$TAG" db-ui-react-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz
63-
npm publish --tag "$TAG" db-ui-v-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz
60+
# https://docs.npmjs.com/generating-provenance-statements#example-github-actions-workflow
61+
npm publish --tag "$TAG" db-ui-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz --provenance
62+
npm publish --tag "$TAG" db-ui-ngx-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz --provenance
63+
npm publish --tag "$TAG" db-ui-react-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz --provenance
64+
npm publish --tag "$TAG" db-ui-v-elements"$PACKAGE_ENDING"-"$VALID_SEMVER_VERSION".tgz --provenance
6465
done

‎.github/workflows/03-publish-packages.yml

+2
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,8 @@ jobs:
2424
fail-fast: false
2525
matrix:
2626
themes: [default, enterprise]
27+
permissions:
28+
id-token: write
2729
steps:
2830
- name: ⬇ Checkout repo
2931
uses: actions/checkout@v4

0 commit comments

Comments
 (0)
Please sign in to comment.