Plan, audit, and safely apply npm trusted publisher configuration for GitHub packages and monorepos.
npm's native npm trust command is the source of truth for configuring OIDC trusted publishing, but
it is not workspace-aware: you have to know each package name, the GitHub repository, and the exact
workflow file, and run the command once per package with manual throttling. trusted-publisher
automates that discovery and bookkeeping for one package or hundreds — without ever guessing.
# scan the current repository, check npm state, and ask before applying
npx -y trusted-publisher
# explicitly apply high-confidence changes without prompting
npx -y trusted-publisher --yes
# scan a public GitHub repository you have not checked out
npx -y trusted-publisher --source https://github.com/owner/repo
# CI-friendly audit with no mutations
npx trusted-publisher --audit --jsonThe CLI discovers publishable npm packages, analyzes GitHub Actions release workflows, checks existing npm trusted publisher state, explains drift, and applies only high-confidence changes.
See packages/trusted-publisher/README.md for the complete
CLI reference and safety details.
trusted-publisher runs a read-only analysis pipeline and only mutates npm once changes are
authorized:
- Discover — resolve the GitHub
owner/repofrom git, find publishable packages across npm/pnpm/Yarn/Lerna/Nx/Turbo layouts, and parse.github/workflows/*.ymlinto publish candidates with evidence. - Map — build the publish topology that links each package to the workflow that releases it (global, per-package, hybrid, or conflicting).
- Plan & score — select the right workflow per package, default to publish + stage-publish
trust permissions, infer the environment, render the exact
npm trust githubcommand, and assign a confidence tier. - Check — compare each plan against live npm state: already configured, needs creating, drifts from an existing record, or is blocked.
- Apply — run
npm trustserially and throttled, only for high-confidence plans, only when authorized.
The full pipeline is documented in docs/architecture.md.
- Local repo and monorepo scanning for npm, Yarn, pnpm, Lerna, Nx, and Turbo layouts.
- Workflow analysis for npm, pnpm, Yarn, Changesets, semantic-release, Lerna, Nx, matrix jobs, and reusable workflows.
- Confidence scoring with a human-readable
explainandreasonstrail. - Trusted publisher drift diffing, field by field, before any replacement.
- JSON and CI audit modes with Markdown migration reports.
- Explicit package claiming for unpublished package names.
- npm scope bulk configuration (
--scope @acme). - Public GitHub source scanning via
--source, without cloning it yourself. - A typed library API in addition to the CLI.
# local repository, ask before applying
npx -y trusted-publisher
# local repository, high-confidence auto-apply
npx -y trusted-publisher --yes
# remote public GitHub repository
npx -y trusted-publisher --source https://github.com/owner/repo
# CI audit without mutation (exit code reflects drift)
npx trusted-publisher --audit --json
# migration report for humans
npx trusted-publisher --dry-run --report trusted-publisher-report.md| Document | What it covers |
|---|---|
| Package README | Full CLI usage, options, modes, and safety model. |
| docs/architecture.md | Pipeline and module overview. |
| docs/detection.md | Package discovery and workflow analysis details. |
| docs/confidence-and-topology.md | Topology, workflow selection, and the scoring model. |
| docs/json-report.md | --json schema and audit exit codes. |
| docs/api.md | Programmatic API reference. |
| docs/positioning.md | Why this tool exists alongside npm trust. |
- Node.js
>=22.14.0 - npm CLI
>=11.15.0(the version that shipsnpm trust) - GitHub Actions workflows under
.github/workflows/ - Packages that already exist on npm — or use
--claimto publish placeholder names first
This repository uses pnpm workspaces, Turborepo, TypeScript, Oxlint, Oxfmt, Vitest, tsdown/Rolldown, Changesets, and Commitizen.
corepack enable
pnpm install
pnpm checkUseful scripts:
pnpm buildbuilds all packages.pnpm testruns Vitest.pnpm lintruns Oxlint.pnpm formatruns Oxfmt.pnpm changesetcreates a release changeset.pnpm commitstarts the Commitizen prompt.
See CONTRIBUTING.md for the full development and release workflow.
The npm package is published from .github/workflows/release.yml
when a matching tag is pushed:
v<version>trusted-publisher@<version>
The release workflow uses npm trusted publishing with GitHub OIDC:
- GitHub Actions permissions include
id-token: write. actions/setup-nodeis configured forregistry-url: https://registry.npmjs.org.- The publish step runs
npm publish --access public --provenance. packages/trusted-publisher/package.jsonalso setspublishConfig.provenance: true.
Before tagging, make sure npm has a trusted publisher entry for this repository and
.github/workflows/release.yml. trusted-publisher can configure that entry for its own repo.