mirror of
https://github.com/actions/setup-node.git
synced 2026-05-15 10:21:22 +00:00
Fix typos in documentation for publishing to npm with Trusted Publisher (OIDC)
This commit is contained in:
parent
6633a8a672
commit
7ff57b903d
@ -477,7 +477,7 @@ Please refer to the [Ensuring workflow access to your package - Configuring a pa
|
|||||||
|
|
||||||
## Publishing to npm with Trusted Publisher (OIDC)
|
## Publishing to npm with Trusted Publisher (OIDC)
|
||||||
|
|
||||||
Npm supports Trusted Publishers, enabling packages to be published from GitHub Actions using OpenID Connect (OIDC) instead of long-lived npm tokens. This improves security by replacing static credentials with short-lived tokens, reducing the risk of credential leakage and simplifying authentication in CI/CD workflows.
|
npm supports Trusted Publishers, enabling packages to be published from GitHub Actions using OpenID Connect (OIDC) instead of long-lived npm tokens. This improves security by replacing static credentials with short-lived tokens, reducing the risk of credential leakage and simplifying authentication in CI/CD workflows.
|
||||||
|
|
||||||
### Requirements
|
### Requirements
|
||||||
|
|
||||||
@ -516,7 +516,7 @@ You must also configure a **Trusted Publisher** in npm for your package/scope th
|
|||||||
* `contents: read` is required for repository access
|
* `contents: read` is required for repository access
|
||||||
* If a Trusted Publisher is configured with a GitHub Actions **environment**, it must also be set on the job (e.g. `environment: release`).
|
* If a Trusted Publisher is configured with a GitHub Actions **environment**, it must also be set on the job (e.g. `environment: release`).
|
||||||
|
|
||||||
OIDC authentication is handled automatically via GitHub’s identity token.
|
OIDC authentication is handled automatically via GitHub's identity token.
|
||||||
|
|
||||||
> **Note**: If the Trusted Publisher configuration (GitHub owner/repo/workflow file, and optional environment) does not match the workflow run identity exactly, publishing may fail with **E404 Not Found** even if the package exists on npm.
|
> **Note**: If the Trusted Publisher configuration (GitHub owner/repo/workflow file, and optional environment) does not match the workflow run identity exactly, publishing may fail with **E404 Not Found** even if the package exists on npm.
|
||||||
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user