Skip to content

Conversation

@bakkot
Copy link
Member

@bakkot bakkot commented Oct 16, 2025

Existing token-based publishing will stop working soon. Anyway, best not to have to store a secrets in settings. See npm docs on trusted publishing. I already set up the package to trust the publish-biblio.yml workflow.

@github-actions
Copy link

The rendered spec for this PR is available at https://tc39.es/ecma262/pr/3706.

@bakkot bakkot added the ready to merge Editors believe this PR needs no further reviews, and is ready to land. label Oct 16, 2025
Copy link
Member

@ljharb ljharb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OIDC and trusted publishing have severe security issues, even worse than our current setup. We should not do this.

@bakkot
Copy link
Member Author

bakkot commented Oct 17, 2025

I'm open to hearing your case for that, but I don't think that's true. Why do you believe that to be so?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready to merge Editors believe this PR needs no further reviews, and is ready to land.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants