mirror of
https://github.com/AgentSeal/codeburn.git
synced 2026-05-20 00:57:09 +00:00
Triggers on v* tag push or manual dispatch. Builds, tests, then publishes codeburn to npm with provenance attestation. Uses OIDC so no NPM_TOKEN is stored in repo secrets. The npm-publish GitHub Environment gates the publish step behind a required reviewer, so every release needs explicit human approval before it reaches the registry. Tag/package version mismatch fails fast before any build work. Tests run before publish to prevent shipping a broken release. |
||
|---|---|---|
| .. | ||
| publish-npm.yml | ||
| release-menubar.yml | ||