npm / npm/documentation

[Feature Request] Document Trusted Publishing for unsupported CI/CD tools

Open
#1,860 0 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
MDX
Stars
712
Forks
4.2k
Avg merge
4d 16h
Merged PRs (30d)
3

Description

I read through the Trusted Publishing documentation and it only displays GitHub and GitLab for Trusted Publishing. However, it does not enlist resources to build our own solution to avoid tokens and use trusted publishing.

While I understand it could be a burden to support a wide variety of CI/CD tools, there are far more thant GitLab and GitHub, even if you think they are the most used tools for publishing an NPM package.

Especially because you warn people on the token settings page when "Bypass 2FA" checkbox is checked to "There are security risks with this option. For automation or CI/CD uses, please use Trusted Publishing instead.". We would like, if we would have an option to.

Please, provide documentations for other CI/CD tools as well, at least endpoints, calls, etc.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the existing Trusted Publishing documentation for GitHub and GitLab and identify what resources are already provided. Research how unsupported CI/CD tools can use Trusted Publishing, including the required endpoints and calls, then document those resources and verify that the guidance addresses token-free publishing.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, gitlab
Domain
ci-cd, devops, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.