Adopt Trusted Publishing and Supply Chain Security Best Practices #1894

Open
opened 2026-02-16 17:33:06 -05:00 by yindo · 1 comment
Owner

Originally created by @AdnaneKhan on GitHub (Sep 30, 2025).

Originally assigned to: @thdxr on GitHub.

As I’m sure you may be aware GitHub recently announced changes to NPM publishing (https://github.blog/changelog/2025-09-29-strengthening-npm-security-important-changes-to-authentication-and-token-management/) and is encouraging projects to switch to trusted publishing as soon as they are able.

OpenCode currently uses a long-lived NPM token for publishing and does not leverage basic features such as branch protection for the default branch.

Can OpenCode adopt these measures to protect downstream users?

Originally created by @AdnaneKhan on GitHub (Sep 30, 2025). Originally assigned to: @thdxr on GitHub. As I’m sure you may be aware GitHub recently announced changes to NPM publishing (https://github.blog/changelog/2025-09-29-strengthening-npm-security-important-changes-to-authentication-and-token-management/) and is encouraging projects to switch to trusted publishing as soon as they are able. OpenCode currently uses a long-lived NPM token for publishing and does not leverage basic features such as branch protection for the default branch. Can OpenCode adopt these measures to protect downstream users?
Author
Owner

@rekram1-node commented on GitHub (Sep 30, 2025):

makes sense

@rekram1-node commented on GitHub (Sep 30, 2025): makes sense
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: anomalyco/opencode#1894