How is this library built and released? Could you please move this to a GitHub Action that can be audited here publicly as well as published on NPM [with provenance](https://docs.npmjs.com/generating-provenance-statements)? Happy to help!