Skip to content

ci: Updating semantic-release/npm and npm in the action#48

Merged
polymesh-bot merged 1 commit intomainfrom
ci/npm-oidc
Feb 23, 2026
Merged

ci: Updating semantic-release/npm and npm in the action#48
polymesh-bot merged 1 commit intomainfrom
ci/npm-oidc

Conversation

@debelio
Copy link
Copy Markdown
Contributor

@debelio debelio commented Feb 20, 2026

Description

Continuation to the npm publshing migration to OIDC.

Changes:

  • main.yml: Add npm upgrade step (OIDC requires npm ≥ 11.5.1, currently the action is using 10.x)
  • package.json: Pin @semantic-release/npm to ^13.1.4, which is the latest version and it supports OIDC
  • yarn.lock: Updated to reflect new @semantic-release/npm

Breaking Changes

JIRA Link

Checklist

  • Updated the Readme.md (if required) ?

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​semantic-release/​npm@​13.1.49810010095100

View full report

@debelio
Copy link
Copy Markdown
Contributor Author

debelio commented Feb 23, 2026

/fast-forward

@polymesh-bot polymesh-bot merged commit 91ff8a0 into main Feb 23, 2026
6 checks passed
@polymesh-bot polymesh-bot deleted the ci/npm-oidc branch February 23, 2026 07:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants