Commit 9bc60a5
ci+release: drop --provenance for internal repos, v0.1.0-alpha.3
npm rejects provenance bundles when the source GitHub repo is
`internal`-visibility, only `public` repos qualify. The OIDC trusted
publisher auth itself is unaffected — provenance is the separate
sigstore attestation layer. Drop the flag and document re-adding it
if the repo goes public.
Co-authored-by: Cursor <cursoragent@cursor.com>1 parent 5b818a2 commit 9bc60a5
2 files changed
Lines changed: 6 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
84 | 84 | | |
85 | 85 | | |
86 | 86 | | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
87 | 91 | | |
88 | 92 | | |
89 | 93 | | |
90 | 94 | | |
91 | 95 | | |
92 | 96 | | |
93 | 97 | | |
94 | | - | |
| 98 | + | |
95 | 99 | | |
96 | 100 | | |
97 | 101 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
0 commit comments