Skip to content

security: gate npm publish behind reviewed npm environment - #30

Open
DamirAGI wants to merge 1 commit into
mainfrom
sec/gate-npm-publish
Open

DamirAGI wants to merge 1 commit into
mainfrom
sec/gate-npm-publish

Conversation

@DamirAGI

@DamirAGI DamirAGI commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

Adds environment: npm to the tag-driven publish job. The npm environment (created 2026-08-03) requires approval from DamirAGI or roosch269 before the job may start, closing the unattended tag-to-npm path flagged in three consecutive Apex monthly checks (06-13, 07-03, 08-01). sdk-python's reviewed pypi environment is the in-house model this copies.

No other workflow change. OIDC trusted publishing is unaffected - npm's Trusted Publisher config does not currently pin an environment; optionally set it to npm on npmjs.com for a tighter binding.

🤖 Generated with Claude Code

@DamirAGI
DamirAGI requested a review from roosch269 as a code owner August 3, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant