npm-trusted-publishing
CommunitySecure npm publishing without long-lived secrets.
Authorpr-pm
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill eliminates the security risks of using long-lived NPM_TOKEN secrets by implementing secure OIDC-based trusted publishing with provenance attestations.
Core Features & Use Cases
- Trusted Publishing: Replace NPM_TOKEN with GitHub Actions OIDC tokens for secure authentication.
- Provenance Attestations: Add cryptographic proof of package origin and build process.
- Monorepo Support: Configure publishing for packages in subdirectories of monorepos.
- Use Case: When setting up a new npm package repository, use this Skill to implement secure publishing workflows that eliminate the risk of leaked long-lived tokens.
Quick Start
Set up npm trusted publishing for a monorepo package by configuring GitHub Actions with id-token: write permissions and adding the correct repository URL in package.json.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: npm-trusted-publishing Download link: https://github.com/pr-pm/prpm/archive/main.zip#npm-trusted-publishing Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.