Files
Fini 7c2f10504b ci(release): publish through npm trusted publishing only, straight to latest
npm login now issues short-lived session tokens, and tokens that bypass 2FA
are being restricted, so a release that depends on either keeps breaking.
Every @zseven-w package now trusts this repository's release.yml (OIDC,
configured with `npm trust github`), so the workflow publishes with no token
secret and nobody has to log in.

The NPM_TOKEN fallback is removed so a token cannot quietly come back. Every
release, prereleases included, now publishes to `latest`: in this 0.x line
each rc is what users should get, and OIDC can only set the tag of the
publish itself; moving a dist-tag afterwards would need a login again.
2026-09-25 05:40:23 +08:00
..