Skip to content

docs: the registry-side trusted publisher is owner work, not a given - #5

Merged
firejune merged 1 commit into
mainfrom
docs/registry-side-status
Aug 23, 2026
Merged

docs: the registry-side trusted publisher is owner work, not a given#5
firejune merged 1 commit into
mainfrom
docs/registry-side-status

Conversation

@firejune

Copy link
Copy Markdown
Owner

Mirrors firejune/headerless#15. The sibling repository's first automated publish runs proved the workflow side end to end and then failed at the registry with ENEEDAUTH — npm finding no trusted publisher to exchange its OIDC token with. The same will happen here on the first release unless the npmjs.com Trusted Publisher form is in place for byteguard / vite-plugin-byteguard (repository byteguard, workflow release.yml, environment blank). Record that honestly: it is owner work the automation can neither do nor verify.

The sibling repository's first automated publish runs proved the
workflow side end to end and then failed at the registry with
ENEEDAUTH — npm finding no trusted publisher to exchange its OIDC
token with. Record the same honest state here: the npmjs.com form is
owner work the automation can neither do nor verify.
@firejune
firejune enabled auto-merge (squash) August 23, 2026 11:28
@firejune
firejune merged commit a52a9c2 into main Aug 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant