NPM Package Publishing

Audit and improve the security posture of npm package publishing: account security, npm trusted publishing strategy, GitHub repository hardening, token removal, release governance, dependency update policy, provenance, and supply-chain risk. Use when the user asks about npm publishing best practices, publishing security, OIDC/trusted publishing strategy, npm token hygiene, release automation posture, Changesets versus changelog strategies, publint, provenance, or auditing an existing publishing pipeline. For writing or debugging the concrete GitHub Actions publish workflow file, use the npm-trusted-publishing-github-workflow skill instead.

schalkneethling 28d824e 2 files · 17.6 KB Updated

File contents

schalkneethling/claude-toolkit/tree/main/skills/npm-publishing-best-practices commit 28d824e25f

Frequently asked questions

npx skillmds@latest add schalkneethling/npm-package-publishing