Skip to content

Conversation

leobalter
Copy link
Contributor

Improve OIDC docs recommending disallowing non-OIDC tokens.

References

@leobalter leobalter requested a review from Copilot August 29, 2025 20:44
@leobalter leobalter requested a review from a team as a code owner August 29, 2025 20:44
Copilot

This comment was marked as outdated.

Copy link

@p- p- left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@leobalter I've added some comments - Feel free to ignore. 😉

2. Select **"Require two-factor authentication and disallow tokens"**
3. Save your changes

This configuration:
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure if this section is needed, I like the one below better (and think it's enough)

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I removed it

Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR enhances the security recommendations in the npm trusted publishers documentation by adding explicit guidance on restricting traditional token access when using OIDC-based publishing.

  • Adds a dedicated section recommending disallowing non-OIDC tokens for maximum security
  • Provides step-by-step instructions for configuring the "disallow tokens" setting
  • Includes migration guidance for transitioning from token-based to trusted publishing

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

leobalter and others added 6 commits September 3, 2025 14:24
…hers.mdx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
…hers.mdx

Co-authored-by: Peter Stöckli <p-@github.com>
…hers.mdx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@leobalter
Copy link
Contributor Author

fixed lint issues and rebased the branch.

Copy link

@p- p- left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good from my side

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants