Repository navigation
Conversation
- Tag-triggered release workflow with build provenance - GitHub Actions pinned by commit SHA, hardened runner - Tag-version match guard before publish - Removes manual publish scripts - Adds SECURITY.md, npm Dependabot tracking, CODEOWNERS for release paths
Bumps the npm_and_yarn group with 1 update in the /playground directory: [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). Updates `astro` from 5.18.2 to 7.3.2 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@7.3.2/packages/astro) --- updated-dependencies: - dependency-name: astro dependency-version: 7.3.2 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
…hore/maintenance-rollup
…nd/npm_and_yarn-a0fd20a96d' into chore/maintenance-rollup # Conflicts: # playground/package.json
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This was referenced Oct 1, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Releases now publish to npm only from GitHub Actions, with provenance and no stored npm token. Dev dependencies are on current minor versions, and the playground runs on astro 7.
This replaces #516, #532 and #540, which are closed in favor of this PR.
Review order
.github/workflows/release.yml: the publish workflow from chore(security): harden npm publish pipeline against supply-chain attacks #516, with two changes. Prerelease tags such asv1.3.27-dev.0now publish under thedevdist-tag, so they never becomelatest. npm is pinned to 11.21.0 instead ofnpm@latest.SECURITY.md,.npmrc,.github/CODEOWNERS,.github/dependabot.yml,package.json: the rest of chore(security): harden npm publish pipeline against supply-chain attacks #516. Thepublish:devandpublish:mainscripts are gone.playground/package.json: astro 7.3 from Bump astro from 5.18.2 to 7.3.2 in /playground in the npm_and_yarn group across 1 directory #540.@astrojs/reactand@astrojs/vueare also bumped to 7, because astro 7 requires them.bun.lockplus the other manifests: the bumps from chore: weekly maintenance — dep bumps #532 (Biome 2.5.5, tsdown 0.21.10, TypeScript 5.9.3, React 19.2, Vue 3.5.40, Nuxt 3.21). All are dev dependencies, so the peer ranges consumers see don't change.playground/www/layouts/Layout.astro: one blank line for the Biome 2.5 import rule. The file also switches from CRLF to LF line endings, because Biome 2.5 formats Astro frontmatter as LF.Before the first release
Someone with npm admin rights has to set up Trusted Publishing for
lenis, followingSECURITY.md. Until that's done, the workflow can't publish.Test plan
bun run buildpassesastro buildinplaygroundbuilds all 10 pages on astro 7.3.5npm pack --dry-runcontains onlydist/,README.md,LICENSEandpackage.jsonv1.3.27tolatestandv1.3.27-dev.0todevtsc --noEmitreports the same 18 errors asmain, andastro checkreports the same 5. Both were already failing and this PR doesn't fix themmain(all already there)