Oss Publish

Set up a secure release process for an open source package so no long-lived publishing token exists to steal. Covers trusted publishing with OIDC, build provenance, and approval-gated release workflows for npm, PyPI, RubyGems, crates.io, NuGet, Maven Central, Hex, pub.dev, and container images, plus the tag-published flow for Go modules and Packagist, on both GitHub Actions and GitLab CI/CD. Use for any request to publish a package or a container image, secure or harden a release process, set up trusted publishing or provenance, generate an SBOM, sign release binaries, publish checksums for release assets, or create a release workflow.

svyatov 14e5415 13 files · 239.0 KB Updated

File contents

svyatov/oss-kit/tree/main/skills/oss-publish commit 14e541552e

Frequently asked questions

npx skillmds@latest add svyatov/oss-publish