Skip to content

fix(cli): disable provenance on self-hosted publish - #345

Merged
shuv1337 merged 1 commit into
integration-v2from
fix-publish-provenance
Jul 28, 2026
Merged

fix(cli): disable provenance on self-hosted publish#345
shuv1337 merged 1 commit into
integration-v2from
fix-publish-provenance

Conversation

@shuv1337

Copy link
Copy Markdown
Collaborator

Summary

  • disable npm Sigstore provenance generation for Blacksmith self-hosted release runners
  • retain OIDC trusted publishing for all packages

Root cause

The 2.0.0-alpha-1 release failed before publishing its first package because npm rejects provenance bundles whose GitHub Actions runner environment is self-hosted.

Validation

  • bun typecheck in packages/cli
  • release ownership/order tests: 7 passed
  • full pre-push typecheck: 32 tasks passed

@shuv1337
shuv1337 merged commit 1fd0b93 into integration-v2 Jul 28, 2026
@shuv1337
shuv1337 deleted the fix-publish-provenance branch July 28, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant