tree-sitter / tree-sitter/workflows

Trusted publishing without access tokens

Open
#46 6 comments 5 reactions 0 assignees View on GitHub

@ObserverOfTime is already working on this.

Since Dec 14, 2025.

  • #54 by @ObserverOfTime — open
Dominant language
No language data
Stars
44
Forks
27
PR merge metrics
No merged PRs in 30d

Description

Npm and pypi support trusted publishing (and probably cargo as well), which is easier to setup and safer than access tokens. I experimented a bit and this does not seem to work with reusable workflows. Is support for this on your agenda?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review issue #46 and the open pull request #54 first, since the work may already be underway. Confirm the scope for trusted publishing in reusable workflows for npm and PyPI, and possibly Cargo; done should be an agreed and working workflow approach without access tokens.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, release
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.