Skip to content

Commit 12ff166

Browse files
authored
Merge pull request #528 from algorandfoundation/chore/update-to-oidc-publishing
Chore/update to OIDC publishing
2 parents c9c63d1 + bac57fe commit 12ff166

12 files changed

+1415
-1545
lines changed

.github/workflows/release.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ concurrency: release
1313
permissions:
1414
contents: write
1515
issues: read
16+
id-token: write
1617

1718
jobs:
1819
ci:
@@ -63,6 +64,8 @@ jobs:
6364
name: Release
6465
needs: build
6566
runs-on: ubuntu-latest
67+
permissions:
68+
id-token: write
6669
steps:
6770
- name: Generate bot token
6871
uses: actions/create-github-app-token@v1
@@ -82,9 +85,10 @@ jobs:
8285

8386
# semantic-release needs node 20
8487
- name: Use Node.js 20.x
85-
uses: actions/setup-node@v3
88+
uses: actions/setup-node@v4
8689
with:
8790
node-version: 20.x
91+
registry-url: 'https://registry.npmjs.org'
8892

8993
- name: Download built package
9094
uses: actions/download-artifact@v4
@@ -105,4 +109,3 @@ jobs:
105109
run: npx semantic-release
106110
env:
107111
GITHUB_TOKEN: ${{ steps.app_token.outputs.token }}
108-
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}

.nsprc

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,7 @@
11
{
2-
"1109842": {
2+
"1112496": {
33
"active": true,
4-
"notes": "Bundled dependency in NPM, which cannot be overriden and has no update available yet.",
5-
"expiry": "2026-01-28"
6-
},
7-
"1112148": {
8-
"active": true,
9-
"notes": "Bundled dependency in NPM via semantic-release chain. Low severity DoS (CWE-400, CWE-1333) in [email protected] parsePatch/applyPatch functions. Cannot be overridden until npm releases updated bundle. Mitigation: Only affects dev dependencies, not production runtime. See GHSA-73rr-hh4g-fpgx",
10-
"expiry": "2026-01-30"
4+
"notes": "undici is used in @semantic-release/npm and this hasn't been fixed",
5+
"expiry": "2026-02-15"
116
}
127
}

0 commit comments

Comments
 (0)