From 069d5cdcf968be201eabf1e5ac055b5d0801dc16 Mon Sep 17 00:00:00 2001 From: Masafumi Koba <473530+ybiquitous@users.noreply.github.com> Date: Mon, 24 Apr 2023 16:12:44 +0900 Subject: [PATCH] feat: set `permissions.id-token: write` for Node.js Release workflow (#18) To support provenance publishing on npm. See https://docs.npmjs.com/generating-provenance-statements --- .github/workflows/nodejs-release-reusable.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/nodejs-release-reusable.yml b/.github/workflows/nodejs-release-reusable.yml index 69ea187..d055b97 100644 --- a/.github/workflows/nodejs-release-reusable.yml +++ b/.github/workflows/nodejs-release-reusable.yml @@ -23,6 +23,7 @@ jobs: runs-on: ubuntu-latest permissions: contents: write + id-token: write timeout-minutes: 10 steps: - name: Checkout