From c666e881e3ccdef976957ace496829ac7b06f34e Mon Sep 17 00:00:00 2001 From: NiftyAndy Date: Tue, 28 Jul 2026 12:01:26 -0400 Subject: [PATCH] fix(docs): clarify package verification --- docs/PUBLISHING.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/PUBLISHING.md b/docs/PUBLISHING.md index 542f9480..2d20b8f6 100644 --- a/docs/PUBLISHING.md +++ b/docs/PUBLISHING.md @@ -21,6 +21,10 @@ Publication occurs only from a Release Please tag; ordinary pushes do not publish. The release workflow fails clearly when npm publication is enabled but neither trusted publishing nor a token is configured. +After enabling publication, make one controlled release and verify both the +registry version and the provenance link before treating the repository as +fully configured. + ## GitHub Releases and GitHub Packages A GitHub Release is release metadata attached to a Git tag. It is independent