Skip to content
Discussion options

You must be logged in to vote

@sergei-maertens I have documented the requirements, expectations and transfer steps I think we should have around transferring NPM package ownership based on your research and my own. Apparently, trusted publishing is also available for NPM, so I have opted to document using that over granular tokens. This automatically adds provenance information on every release, which is quite a nice benefit. See that documentation page for more information.

Here's a screenshot of provenance information grabbed from that docs page:


Here are the PRs. Would love to hear if you have anything to add 🙏

Replies: 4 comments 20 replies

Comment options

You must be logged in to vote
1 reply
@sergei-maertens
Comment options

Comment options

You must be logged in to vote
9 replies
@sergei-maertens
Comment options

@tim-schilling
Comment options

@tim-schilling
Comment options

@sergei-maertens
Comment options

@sergei-maertens
Comment options

Comment options

You must be logged in to vote
9 replies
@tim-schilling
Comment options

@Stormheg
Comment options

@sergei-maertens
Comment options

@Stormheg
Comment options

Answer selected by sergei-maertens
@sergei-maertens
Comment options

@sergei-maertens
Comment options

@sergei-maertens
Comment options

@Stormheg
Comment options

Comment options

You must be logged in to vote
1 reply
@sergei-maertens
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants