瀏覽代碼

fix(ci): set NPM_CONFIG_PROVENANCE to true

Lucas Nogueira 1 年之前
父節點
當前提交
85c2d6302e
共有 3 個文件被更改,包括 5 次插入3 次删除
  1. 2 2
      .changes/config.json
  2. 1 0
      .github/workflows/covector-version-or-publish.yml
  3. 2 1
      .github/workflows/publish-cli-js.yml

+ 2 - 2
.changes/config.json

@@ -113,8 +113,8 @@
           "pipe": true
         },
         {
-          "command": "pnpm publish --access public --loglevel silly --tag next --provenance --no-git-checks",
-          "dryRunCommand": "npm publish --dry-run --access public --provenance --no-git-checks",
+          "command": "pnpm publish --access public --loglevel silly --tag next --no-git-checks",
+          "dryRunCommand": "npm publish --dry-run --access public --no-git-checks",
           "pipe": true
         },
         {

+ 1 - 0
.github/workflows/covector-version-or-publish.yml

@@ -92,6 +92,7 @@ jobs:
         env:
           NODE_AUTH_TOKEN: ${{ secrets.ORG_NPM_TOKEN }}
           CARGO_AUDIT_OPTIONS: ${{ secrets.CARGO_AUDIT_OPTIONS }}
+          NPM_CONFIG_PROVENANCE: true
         with:
           command: 'version-or-publish'
           token: ${{ secrets.GITHUB_TOKEN }}

+ 2 - 1
.github/workflows/publish-cli-js.yml

@@ -390,8 +390,9 @@ jobs:
       - name: Publish
         run: |
           echo "//registry.npmjs.org/:_authToken=$NPM_TOKEN" >> ~/.npmrc
-          npm publish --tag next --provenance
+          npm publish --tag next
         env:
           GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
           NPM_TOKEN: ${{ secrets.ORG_NPM_TOKEN }}
           RELEASE_ID: ${{ github.event.client_payload.releaseId || inputs.releaseId }}
+          NPM_CONFIG_PROVENANCE: true