From 4027b892084d65e15ae4ea6669bff38f119e21a9 Mon Sep 17 00:00:00 2001 From: Daniel Roe Date: Mon, 8 Jun 2026 09:42:28 +0100 Subject: [PATCH] =?UTF-8?q?docs:=20hat=20tip=20to=20@e18e/setup-publish=20?= =?UTF-8?q?and=20setup-trusted-publishing=20=E2=9D=A4=EF=B8=8F?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- README.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index c9dbd67..31b8b5a 100644 --- a/README.md +++ b/README.md @@ -27,6 +27,9 @@ The aim of **uppt** is to make a very simple, secure release workflow for mainta **4.** Add the following workflow to your repo in `.github/workflows/release.yml`, and you're done! +> [!TIP] +> [`@e18e/setup-publish`](https://github.com/e18e/setup-publish) can scaffold this file for you. Run `npx @e18e/setup-publish` and pick the `uppt` template (interactive prompts will ask for your package manager and the GitHub environment name; pass `--env npm` to match the trusted-publisher entry from step 1). + ```yaml name: release @@ -226,7 +229,7 @@ For `publish` to work end to end you need: - An npmjs.com trusted-publisher entry per package, pointing at the caller's `release.yml` and the `npm` environment, with the `npm stage publish` permission chip. - A GitHub environment named `npm` (or whichever name you put on the publish job). -- The package must already exist on npmjs.com; `npm stage publish` cannot stage a brand-new package. +- The package must already exist on npmjs.com; `npm stage publish` cannot stage a brand-new package. For the very first publish, [`setup-trusted-publishing`](https://github.com/ThisIsMissEm/setup-trusted-publishing) will publish a `0.0.0` stub so you can attach a trusted-publisher entry: `npx setup-trusted-publishing` (run once, from the package directory). ## Credits -- 2.51.2