chore: 更新 npm publish 工作流程,升級 actions 版本並使用 --provenance 進行發布

This commit is contained in:
myw
2026-06-11 00:43:29 +08:00 Unverified
parent 7a56b7b4eb
commit 4b02482723
+15 -7
View File
@@ -3,17 +3,25 @@ name: npm publish
on:
release:
types: [created]
jobs:
build:
runs-on: ubuntu-latest
# 這是 Trusted Publishing 必須的權限
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@v2
# Setup .npmrc file to publish to npm
- uses: actions/setup-node@v1
- uses: actions/checkout@v4 # 建議升級至較新版本的 checkout
- uses: actions/setup-node@v4 # 建議升級至較新版本的 setup-node
with:
node-version: '12.x'
node-version: '20.x' # 建議換成你目前使用的 Node LTS 版本
registry-url: 'https://registry.npmjs.org'
- run: npm install
- run: npm publish
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
# 使用 --provenance 進行發布,OIDC 自動完成驗證,不再需要 env.NODE_AUTH_TOKEN
- run: npm publish --provenance