<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Github-Actions on Tokenise</title><link>https://tokenise.rosvetic.com/tags/github-actions/</link><description>Recent content in Github-Actions on Tokenise</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 08 Oct 2026 16:03:00 +0000</lastBuildDate><atom:link href="https://tokenise.rosvetic.com/tags/github-actions/index.xml" rel="self" type="application/rss+xml"/><item><title>Let the agent cut the release, keep the approve button for yourself: npm staged publishing from Actions</title><link>https://tokenise.rosvetic.com/posts/npm-staged-publish-agent-release/</link><pubDate>Thu, 08 Oct 2026 16:03:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/npm-staged-publish-agent-release/</guid><description>&lt;p&gt;Picture the release step in a repo where a coding agent does a lot of the work. It bumps the version, writes the changelog from the merged PRs, opens the release PR. Then somebody has to publish, and the publish credential has to live somewhere the automation can reach it. That&amp;rsquo;s the part nobody loves: either a long-lived npm token in CI secrets, or a human at a laptop typing a one-time code.&lt;/p&gt;</description></item></channel></rss>