Skip to content

Maintenance: migrate package publishing to OIDC #4649

@sthulb

Description

@sthulb

Summary

We should migrate package publishing to OIDC based tokens.

https://github.blog/changelog/2025-07-31-npm-trusted-publishing-with-oidc-is-generally-available/

Why is this needed?

To create a more secure
Release pipeline.

Which area does this relate to?

Automation

Solution

No response

Acknowledgment

Future readers

Please react with 👍 and your use case to help us understand customer demand.

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmedThe scope is clear, ready for implementationinternalPRs that introduce changes in governance, tech debt and chores (linting setup, baseline, etc.)

    Type

    No type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions