Skip to content

docs: record npm package bootstrap - #2

Merged
kestiny18 merged 1 commit into
mainfrom
codex/npm-bootstrap-guidance
Aug 15, 2026
Merged

docs: record npm package bootstrap#2
kestiny18 merged 1 commit into
mainfrom
codex/npm-bootstrap-guidance

Conversation

@kestiny18

Copy link
Copy Markdown
Owner

What

  • document the one-time bootstrap required before a new npm package can use per-package Trusted Publishing
  • require an isolated owner login, a 0.0.0 placeholder, exact Trusted Publisher settings, and registry verification
  • record npm's first-publish latest behavior and cleanup expectations

Why

A brand-new npm package has no settings page for Trusted Publisher configuration, so OIDC-only first publication fails until the package record exists.

Checks

  • git diff --check
  • verified dsh-redact@0.1.0 and latest in the npm registry
  • verified SLSA provenance attestation is present

@kestiny18
kestiny18 merged commit c719073 into main Aug 15, 2026
2 checks passed
@kestiny18
kestiny18 deleted the codex/npm-bootstrap-guidance branch August 15, 2026 03:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant