-
Notifications
You must be signed in to change notification settings - Fork 69
41 lines (34 loc) · 1.18 KB
/
Copy pathpackage-drift.yml
File metadata and controls
41 lines (34 loc) · 1.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
name: Package Drift
# Read-only drift detection for npm package publishing access, comparing the
# live registry against src/config/packageAccess.ts. Mutations are applied by
# a human via the generated remediation plan (npm requires an interactive 2FA
# challenge for all governance writes); PyPI has no API and is not checked.
#
# Requires the NPM_READ_TOKEN secret: a read-only npm granular access token
# with organization read access to "modelcontextprotocol". When the secret is
# absent the check prints a skip notice and passes (same optional-credential
# pattern as the Discord integration).
on:
schedule:
- cron: '0 14 * * 1' # Mondays 14:00 UTC
workflow_dispatch:
permissions:
contents: read
jobs:
npm-drift:
name: npm package access drift
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Check npm package access drift
env:
NPM_TOKEN: ${{ secrets.NPM_READ_TOKEN }}
run: npm run check-package-drift