Files
irl-dan 1a00283226 ci(reactor-publish): use npm publish for OIDC trusted publishing
pnpm publish does not support npm's OIDC token exchange, so the tag-triggered
publish job would have no auth in CI. Switch to pnpm pack (which rewrites each
package's workspace:* SDK dep to the concrete version + runs prepack) then
npm publish the tarball, which npm >=11.5.1 publishes via the GitHub Actions
OIDC token + provenance. Order, per-package version, and idempotent skip are
unchanged. Release runbook lives in the private platform docs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 19:29:50 -07:00
..