From 7afeb91daf6e7d51ce196ebc0be097b2e2e6c5f6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=D0=A0=D0=BE=D0=B1=D0=BE=D1=82?= Date: Mon, 28 Sep 2026 01:35:21 +0200 Subject: [PATCH] Record the unattended 0.1.2 publish (run 36359053252, provenance) Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/evidence/releases/2026-09-28-npm/README.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/docs/evidence/releases/2026-09-28-npm/README.md b/docs/evidence/releases/2026-09-28-npm/README.md index 35c2328..a23b9cd 100644 --- a/docs/evidence/releases/2026-09-28-npm/README.md +++ b/docs/evidence/releases/2026-09-28-npm/README.md @@ -11,3 +11,12 @@ A skipped or green-but-idle publish job proves nothing; the proof is an unpublished version appearing on the registry from the tag alone. + +## Observed after the tag + +`v0.1.2` → release run 36359053252: jobs `validate`, `House skill audit`, `release` and +**`publish`** all `success` (the publish job ran, it did not skip). The registry then served +`dist-tags.latest = 0.1.2` with a SLSA v1 provenance attestation +(`npm view @ssheleg/web3d-dev@0.1.2 dist.attestations.provenance`). No token was used; the +publish authenticated through GitHub OIDC. +