Skip to content

Conversation

@jasonpraful
Copy link
Member

@jasonpraful jasonpraful commented Jan 22, 2026

Migrate from CircleCI to GitHub Actions to enable OIDC trusted publishing and provenance attestation generation.

https://docs.npmjs.com/trusted-publishers

Use OIDC trusted publishing for npm releases instead of token-based auth.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
jobs:
validate:
name: Validate Release
runs-on: ubuntu-latest
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we really want latest? will this backfire when the node versions miss match in the future?
I see it as a future-risk, but not really right now.

this is just a nit btw

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This wouldn't be a concern in this case we are pinning the OS of the GH Action runner, not Node. Node is still pinned to 22.14.0

https://github.com/intercom/intercom-react-native/pull/360/changes/BASE..290093698d7ef8078a1d6962858bf1beefb0fde9#diff-87db21a973eed4fef5f32b267aa60fcee5cbdf03c67fafdc2a9b553bb0b15f34R57

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants