Skip to content
Kotoshu Kotoshu 言修
News

2026-09-05 event. 5 September 2026

Keyless publishing on every channel

Releases now reach npm, RubyGems, and crates.io through CI-held OIDC trust — no long-lived tokens stored anywhere.

  1. npm publishes @kotoshu/client and @kotoshu/wasm keyless: the release workflow exchanges GitHub’s OIDC identity for registry trust, and every artifact carries a provenance attestation.
  2. crates.io trusted publishing (RFC 3691) is registered and verified for the kotoshu crate — the exchange was proven by a smoke dispatch before the first release. The first publish of a crate still needs a token; keyless covers 0.1.1 onward.
  3. RubyGems is wired the same way — the gem’s release workflow plus the owner-side registration — so gem push never runs on a stored credential.

see also kotoshu-rs — publishing ledger npm provenance crates.io trusted publishing