Files
Katerina Skroumpelou ea17d2fdf1 chore(ci): split publish from build, drop Actions cache from privileged workflows (#62)
Splits release.yml into two jobs to close the OIDC-theft path that the
TanStack/router compromise (2026-05-11) exploited:

- `build` job: contents: write + pull-requests: write (release-please).
  Runs install/build/pack and uploads the .tgz as an artifact. NO id-token.
- `publish-npm` job: needs build, id-token: write only. Downloads the
  tarball into a scratch dir and runs `npm publish --provenance`. Never
  executes pnpm install or any third-party code.

JSR publish and GH pre-release stay in the build job (JSR uses its own
OIDC binding scoped to JSR, not npm).

Also drops `cache: pnpm` from docs.yml and ci.yml. Per
adnanthekhan.com/2024/05/06/the-monsters-in-your-build-cache, GitHub
Actions cache poisoning lets a compromised dep on a main-branch workflow
steal the cache token and poison entries that other privileged workflows
on main will restore. release.yml never used cache; docs.yml has
id-token: write for Pages OIDC and is the main remaining target. ci.yml
is low impact but dropped for consistency. preview-release.yml runs in
fork cache scope and is unaffected.

All `\${{ ... }}` substitutions in inline shell scripts moved to env:
blocks (GHSL Part 2 defense in depth, even though upstream values are
regex-validated).

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 13:41:45 +02:00
..