Skip to content

ci: drop redundant --provenance flag - #6

Closed
waterbang wants to merge 1 commit into
mainfrom
ci/npm-trusted-publishing
Closed

waterbang wants to merge 1 commit into
mainfrom
ci/npm-trusted-publishing

Conversation

@waterbang

Copy link
Copy Markdown
Collaborator

Follow-up to #5. Under npm Trusted Publishing, provenance is generated automatically (npm docs: "you don't need to add the --provenance flag"). The explicit flag was redundant on the OIDC path and only added a failure mode on the transitional token fallback (attestation upload failure would fail the publish). Removing it makes the publish command match the documented form: npm publish --tag <tag> --access public.

Trusted Publishing generates provenance automatically; the explicit flag
only added a failure mode for the transitional token fallback.
@waterbang waterbang closed this Sep 19, 2026
@waterbang
waterbang deleted the ci/npm-trusted-publishing branch September 19, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant