← Home

@semantic-release/github

semantic-release plugin to publish a GitHub release and comment on released Pull Requests/Issues

66
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pvdlgsemantic-release-botgr2mtravi

Keywords

gitgithubissuenotificationspublishpull-requestreleasesemantic-releaseversion

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): semantic-release/github migrated from semantic-release-bot to GitHub Actions publishing with SLSA provenance. This is a legitimate, security-improving workflow change consistent with the org's CI/CD practices. ai
publish-pattern new-deps-added AI (publish-pattern): undici is the official Node.js HTTP client maintained by the Node.js core team; its addition to a GitHub API plugin is entirely reasonable and not a supply chain risk. ai

Versions (showing 66 of 166)

Version Deps Published
5.3.3 17 / 14
5.3.2 17 / 14
5.3.1 17 / 14
5.3.0 17 / 14
5.2.12 17 / 14
5.2.11 17 / 14
5.2.10 17 / 14
5.2.9 17 / 14
5.2.8 17 / 14
5.2.7 17 / 14
5.2.6 17 / 14
5.2.5 17 / 14
5.2.4 17 / 14
5.2.3 17 / 14
5.2.2 17 / 14
5.2.1 17 / 14
5.2.0 17 / 14
5.1.0 17 / 14
5.0.6 17 / 14
5.0.5 17 / 14
5.0.4 17 / 14
5.0.3 17 / 14
5.0.2 17 / 14
5.0.1 17 / 14
5.0.0 16 / 14
4.4.2 16 / 14
4.4.1 16 / 14
4.4.0 16 / 14
4.3.0 16 / 14
4.2.18 14 / 12
4.2.17 14 / 12
4.2.16 14 / 12
4.2.15 14 / 12
4.2.14 14 / 12
4.2.13 14 / 12
4.2.12 14 / 12
4.2.11 14 / 12
4.2.10 14 / 12
4.2.9 14 / 12
4.2.8 13 / 12
4.2.7 13 / 12
4.2.6 13 / 12
4.2.5 13 / 12
4.2.4 13 / 12
4.2.3 13 / 12
4.2.2 13 / 12
4.2.1 13 / 12
4.1.3 12 / 14
4.1.2 12 / 14
4.1.1 12 / 14
4.1.0 12 / 14
4.0.3 10 / 14
4.0.2 10 / 14
4.0.1 10 / 14
4.0.0 10 / 14
3.0.3 10 / 14
3.0.2 10 / 14
3.0.1 10 / 14
3.0.0 10 / 14
2.2.3 10 / 14
2.2.2 9 / 14
2.2.1 9 / 13
2.2.0 9 / 13
2.1.0 6 / 13
2.0.0 6 / 13
1.0.0 6 / 19