logoalt Hacker News

woodruffwlast Thursday at 12:42 AM1 replyview on HN

"Trusted Publishing" is just a term of art for OIDC. NPM can and should support federating with CI/CD platforms other than GitHub Actions, to avoid even the appearance of impropriety.

(It makes sense that they'd target GHA first, since that's where the majority of their users probably are. But the technique itself is fundamentally platform agnostic and interoperable.)


Replies

thaynelast Thursday at 2:05 AM

Currently only GHA and Gitlab are supported.