diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 8914859..cdbf777 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -5,9 +5,17 @@ on: branches: - master +permissions: + contents: read + jobs: release: runs-on: ubuntu-latest + permissions: + contents: write + issues: write + pull-requests: write + id-token: write steps: - name: Checkout repository uses: actions/checkout@v4 @@ -18,9 +26,12 @@ jobs: node-version: '20.13.1' - name: Install dependencies - run: npm install + run: npm clean-install + - name: Verify the integrity of provenance attestations and registry signatures for installed dependencies + run: npm audit signatures + - name: Run semantic-release env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} - run: npx semantic-release --debug + run: npx semantic-release