CI (release.yml) cannot publish — no NPM_TOKEN, no Trusted Publishing — so every release (2.0.0→2.11.0) went out via maintainer CLI with no provenance. The workflow is already OIDC-ready (id-token: write).
Action (maintainer, ~2 min, one-time): npmjs.com → package keyoku → Settings → Trusted Publishing → add repo Keyoku-ai/keyoku, workflow release.yml. See docs/PUBLISHING.md.
Done when: a pushed tag publishes automatically from CI with provenance.
CI (
release.yml) cannot publish — noNPM_TOKEN, no Trusted Publishing — so every release (2.0.0→2.11.0) went out via maintainer CLI with no provenance. The workflow is already OIDC-ready (id-token: write).Action (maintainer, ~2 min, one-time): npmjs.com → package
keyoku→ Settings → Trusted Publishing → add repoKeyoku-ai/keyoku, workflowrelease.yml. Seedocs/PUBLISHING.md.Done when: a pushed tag publishes automatically from CI with provenance.