logoalt Hacker News

lloydatkinsonlast Wednesday at 9:20 PM2 repliesview on HN

Just to be clear, "trusted publishing" means a type of reverse vendor lock in? Only some CI systems are allowed to be used for it.


Replies

woodruffwlast Thursday at 12:42 AM

"Trusted Publishing" is just a term of art for OIDC. NPM can and should support federating with CI/CD platforms other than GitHub Actions, to avoid even the appearance of impropriety.

(It makes sense that they'd target GHA first, since that's where the majority of their users probably are. But the technique itself is fundamentally platform agnostic and interoperable.)

show 1 reply
LtWorflast Wednesday at 9:23 PM

Yes. You cannot set up your own.