Skip to content

Conversation

@benjaminleonard
Copy link
Collaborator

@benjaminleonard benjaminleonard commented Sep 23, 2025

Making some improvements to improve security on repos that are publishing to npm:

  • Use trusted publishing for NPM
  • Remove GH_TOKEN use default Github one
  • Remove outdated actions
  • Update dependabot
  • Revoke old tokens
  • Environment
    • Require workflow approval
    • Add to workflows
  • Branch protection
  • Remove unnecessary jobs
📦 Published PR as canary version: 1.1.4--canary.48.17944495194.0

✨ Test out this PR locally via:

npm install @oxide/react-asciidoc@1.1.4--canary.48.17944495194.0
# or 
yarn add @oxide/react-asciidoc@1.1.4--canary.48.17944495194.0

@benjaminleonard benjaminleonard added the patch Increment the patch version when merged label Sep 23, 2025
@benjaminleonard benjaminleonard marked this pull request as ready for review September 23, 2025 11:23
@benjaminleonard
Copy link
Collaborator Author

That validate labels action is deleting, not sure why its still running since I moved it into the release.yml file. Guessing it'll disappear after merging.

@benjaminleonard benjaminleonard merged commit ea8bdd8 into main Sep 23, 2025
4 of 5 checks passed
@github-actions
Copy link

🚀 PR was released in v1.1.4 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch Increment the patch version when merged released

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants