Skip to content

[Feature Request] Document Trusted Publishing for unsupported CI/CD tools #1860

@hron84

Description

@hron84

I read through the Trusted Publishing documentation and it only displays GitHub and GitLab for Trusted Publishing. However, it does not enlist resources to build our own solution to avoid tokens and use trusted publishing.

While I understand it could be a burden to support a wide variety of CI/CD tools, there are far more thant GitLab and GitHub, even if you think they are the most used tools for publishing an NPM package.

Especially because you warn people on the token settings page when "Bypass 2FA" checkbox is checked to "There are security risks with this option. For automation or CI/CD uses, please use Trusted Publishing instead.". We would like, if we would have an option to.

Please, provide documentations for other CI/CD tools as well, at least endpoints, calls, etc.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions