Skip to content

[Dependency Mgmt] Set up trusted publishing for CommonGrants npm packages #765

@laurabelinfante

Description

@laurabelinfante

Summary

Configure trusted publishing for CommonGrants npm packages to eliminate the need to rotate npm tokens stored in GitHub Actions. Trusted publishing lets GitHub Actions authenticate to npm without long-lived tokens. May require GitHub org admin approval. PyPI trusted publishing for common-grants-sdk is out of scope here and will be tracked separately (see #650).

Acceptance criteria

  • Trusted publishing configured for CommonGrants npm packages
  • Token-based npm auth removed from GitHub Actions workflows
  • Required GitHub org admin approvals secured if needed
  • Publishing of npm packages is verified for all packages switched to trusted publishing

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No fields configured for Task.

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions