npm-trusted-publishing

Installation
SKILL.md

NPM Trusted Publishing

Overview

Set up secure npm publishing from GitHub Actions using OIDC trusted publishing instead of long-lived NPM_TOKEN secrets.

When to Use

  • Setting up npm publish workflow in GitHub Actions
  • Migrating from NPM_TOKEN to trusted publishing
  • Adding provenance attestations to packages
  • Publishing monorepo packages

Quick Reference

Requirement Implementation
GitHub Actions permission id-token: write
package.json field repository.url matching GitHub repo
Related skills
Installs
14
Repository
pr-pm/prpm
GitHub Stars
108
First Seen
Jan 25, 2026