Commit 85cb764
chore: migrate to npm trusted publishing and GitHub App token
- Replace PAT with GitHub App token (RELEASE_BOT_APP_ID/PRIVATE_KEY) in
release job; app token events trigger other workflows unlike GITHUB_TOKEN
- Remove npm publish from semantic-release; add separate publish.yml
workflow triggered on version tags using OIDC (no NPM_TOKEN needed)
- Drop id-token: write and write permissions from release job (governed
by app installation, not workflow permissions block)
- Add windows-test to release job dependencies
- Remove @semantic-release/npm plugin from .releaserc.yaml
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 5fde6c1 commit 85cb764
3 files changed
Lines changed: 31 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
| 61 | + | |
66 | 62 | | |
67 | | - | |
| 63 | + | |
68 | 64 | | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
69 | 71 | | |
70 | 72 | | |
71 | 73 | | |
72 | | - | |
| 74 | + | |
73 | 75 | | |
74 | 76 | | |
75 | | - | |
76 | 77 | | |
77 | | - | |
78 | | - | |
79 | | - | |
| 78 | + | |
| 79 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
12 | 11 | | |
13 | 12 | | |
0 commit comments