Is it just me, or is #npm's trusted publishing unnecessarily rigid?
-
Is it just me, or is #npm's trusted publishing unnecessarily rigid? Only one workflow filename allowed per package. It's like they never imagined a project having multiple release branches or evolving CI structures. Moving from build.yaml to publish.yaml shouldn't be this annoying. 😩
-
@hongminhee It's just early days I think. Another limitation is that it is tied to GitHub/GitLab.
-
@hongminhee It's just early days I think. Another limitation is that it is tied to GitHub/GitLab.
@bart@floss.social Spot on. The vendor lock-in is exactly what's holding me back from moving to Codeberg. It's frustrating that standard security features like OIDC publishing are becoming a golden cage that keeps us tied to big platforms. I'd love to see npm support OIDC from Forgejo/Gitea, but it feels like we're still a long way from a truly forge-agnostic ecosystem. 2FA tokens for life, I guess? 🥲