mirror of
https://github.com/ZSeven-W/dsh-openpencil.git
synced 2026-09-28 09:02:55 +08:00
npm login now issues short-lived session tokens, and tokens that bypass 2FA are being restricted, so a release that depends on either keeps breaking. Every @zseven-w package now trusts this repository's release.yml (OIDC, configured with `npm trust github`), so the workflow publishes with no token secret and nobody has to log in. The NPM_TOKEN fallback is removed so a token cannot quietly come back. Every release, prereleases included, now publishes to `latest`: in this 0.x line each rc is what users should get, and OIDC can only set the tag of the publish itself; moving a dist-tag afterwards would need a login again.