報せNews
2026-09-05 報 event. 5 September 2026
Keyless publishing on every channel
Releases now reach npm, RubyGems, and crates.io through CI-held OIDC trust — no long-lived tokens stored anywhere.
- npm publishes
@kotoshu/clientand@kotoshu/wasmkeyless: the release workflow exchanges GitHub’s OIDC identity for registry trust, and every artifact carries a provenance attestation. - crates.io trusted publishing (RFC 3691) is registered and verified for the
kotoshucrate — the exchange was proven by a smoke dispatch before the first release. The first publish of a crate still needs a token; keyless covers 0.1.1 onward. - RubyGems is wired the same way — the gem’s release workflow plus the owner-side registration — so
gem pushnever runs on a stored credential.
see also kotoshu-rs — publishing ledger npm provenance crates.io trusted publishing