1
0
Fork 0
mirror of https://github.com/mozilla/pdf.js.git synced 2025-04-19 06:38:07 +02:00

Generate provenance statements on npm publish

This PR adds [Provenance statements](https://docs.npmjs.com/generating-provenance-statements) on `npm publish`, increasing supply-chain security.
This commit is contained in:
Wojciech Maj 2024-07-01 13:16:16 +02:00
parent b5d554e1b4
commit aaa65bf3fc
No known key found for this signature in database
GPG key ID: 2BAFB575E3D38592

View file

@ -4,6 +4,7 @@ on:
types: [published]
permissions:
contents: read
id-token: write
jobs:
publish:
@ -33,6 +34,6 @@ jobs:
run: npx gulp dist
- name: Publish the `pdfjs-dist` library to NPM
run: npm publish ./build/dist
run: npm publish ./build/dist --provenance
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}